5

CVE-2004-1720

Exploit
The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. NOTE: it is unclear whether the calendar.html is an exposure, since the path is leaked in web logs that may only be available to the administrators, who would have access to the path through legitimate means.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MerakMail Server Version7.4.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.89% 0.94
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=109279057326044&w=2
http://packetstormsecurity.nl/0408-exploits/merak527.txt
Patch
Vendor Advisory
Exploit
http://secunia.com/advisories/12269
Patch
Vendor Advisory
Exploit
http://securitytracker.com/id?1010969
http://www.securityfocus.com/bid/10966
Patch
Vendor Advisory
Exploit
http://www.osvdb.org/9043
Patch
Vendor Advisory
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/17027