Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to create or rename arbitrary mail directories via the mailbox name argument of the (1) create or (2) rename commands.
References
Link | Resource |
---|---|
http://secunia.com/secunia_research/2005-59/advisory/ | Patch Vendor Advisory |
http://www.mailenable.com/hotfix/ | Patch |
http://secunia.com/advisories/17633 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/15494 | |
http://securitytracker.com/id?1015239 | |
http://www.vupen.com/english/advisories/2005/2484 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-11-18 17:03
Updated : 2011-03-07 18:26
NVD link : CVE-2005-3691
Mitre link : CVE-2005-3691
JSON object : View
CWE
Products Affected
mailenable
- mailenable_professional
- mailenable_enterprise