The (1) function.php or (2) function.view.php scripts in Merak Mail Server 5.2.7 allow remote attackers to read arbitrary PHP files via a direct HTTP request to port 32000.
References
Link | Resource |
---|---|
http://packetstormsecurity.nl/0408-exploits/merak527.txt | Patch Vendor Advisory |
http://www.securityfocus.com/bid/10966 | Patch Vendor Advisory |
http://www.osvdb.org/9045 | Patch Vendor Advisory |
http://secunia.com/advisories/12269 | Patch Vendor Advisory |
http://securitytracker.com/id?1010969 | |
http://marc.info/?l=bugtraq&m=109279057326044&w=2 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17029 |
Configurations
Information
Published : 2004-08-16 21:00
Updated : 2017-07-10 18:31
NVD link : CVE-2004-1721
Mitre link : CVE-2004-1721
JSON object : View
CWE
Products Affected
merak
- mail_server