LOW · 2.1

CVE-2005-1490

Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2, when the mailbox.dat file does not exist, allows remote authenticated users to determine if a file exists via the folder parameter to attachment.ht...

Vulnerability Description

Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2, when the mailbox.dat file does not exist, allows remote authenticated users to determine if a file exists via the folder parameter to attachment.html.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IcewarpWeb Mail5.4.2
MerakMail Server8.0.3

References

FAQ

What is CVE-2005-1490?

CVE-2005-1490 is a vulnerability with a CVSS score of 2.1 (LOW). Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2, when the mailbox.dat file does not exist, allows remote authenticated users to determine if a file exists via the folder parameter to attachment.ht...

How severe is CVE-2005-1490?

CVE-2005-1490 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-1490?

Check the references section above for vendor advisories and patch information. Affected products include: Icewarp Web Mail, Merak Mail Server.