CVE Vulnerabilities

CVE-2005-1491

Published: May 11, 2005 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to (1) move their home directory via viewaction.html or (2) move arbitrary files via the importfile parameter to importaction.html.

Affected Software

Name Vendor Start Version End Version
Web_mail Icewarp 5.4.2 5.4.2
Mail_server Merak 8.0.3 8.0.3

References