Vulnerability Description
Open WebMail 2.30 and earlier, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which allows remote attackers to create arbitrary directories.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open Webmail | Open Webmail | 1.7 |
References
- http://openwebmail.org/openwebmail/download/cert/patches/SA-04:02/openwebmail.plPatch
- http://secunia.com/advisories/11334Vendor Advisory
- http://www.securityfocus.com/bid/10087Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15822
- http://openwebmail.org/openwebmail/download/cert/patches/SA-04:02/openwebmail.plPatch
- http://secunia.com/advisories/11334Vendor Advisory
- http://www.securityfocus.com/bid/10087Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15822
FAQ
What is CVE-2004-2458?
CVE-2004-2458 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Open WebMail 2.30 and earlier, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which allows remote attackers to create arbitrary directo...
How severe is CVE-2004-2458?
CVE-2004-2458 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2458?
Check the references section above for vendor advisories and patch information. Affected products include: Open Webmail Open Webmail.