Описание
MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to bwlist_inc.html, which reveals the path in an error message.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:icewarp:web_mail:5.5.1:*:*:*:*:*:*:*
cpe:2.3:a:merak:mail_server:8.2.4r:*:*:*:*:*:*:*
EPSS
Процентиль: 57%
0.00346
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to bwlist_inc.html, which reveals the path in an error message.
EPSS
Процентиль: 57%
0.00346
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other