MEDIUM · 5.0

CVE-2004-2572

AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters such as "()" or (2) a large number of characters in the Lookup field on the net...

Vulnerability Description

AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters such as "()" or (2) a large number of characters in the Lookup field on the netaddressbook.php web form, which reveals the path in an ldaplib.php error message when the ldap_search function fails, due to improper processing of the $keyword variable.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Amax Information TechnologiesMagic Winmail Server3.6

References

FAQ

What is CVE-2004-2572?

CVE-2004-2572 is a vulnerability with a CVSS score of 5.0 (MEDIUM). AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters such as "()" or (2) a large number of characters in the Lookup field on the net...

How severe is CVE-2004-2572?

CVE-2004-2572 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-2572?

Check the references section above for vendor advisories and patch information. Affected products include: Amax Information Technologies Magic Winmail Server.