Описание
Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to create or rename arbitrary mail directories via the mailbox name argument of the (1) create or (2) rename commands.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
- Patch
- PatchVendor Advisory
- PatchVendor Advisory
- Patch
Уязвимые конфигурации
Конфигурация 1Версия до 1.6 (включая)
Одно из
cpe:2.3:a:mailenable:mailenable_enterprise:1.00:*:*:*:*:*:*:*
cpe:2.3:a:mailenable:mailenable_enterprise:1.1:*:*:*:*:*:*:*
cpe:2.3:a:mailenable:mailenable_enterprise:1.01:*:*:*:*:*:*:*
cpe:2.3:a:mailenable:mailenable_enterprise:1.02:*:*:*:*:*:*:*
cpe:2.3:a:mailenable:mailenable_enterprise:1.03:*:*:*:*:*:*:*
cpe:2.3:a:mailenable:mailenable_enterprise:1.04:*:*:*:*:*:*:*
cpe:2.3:a:mailenable:mailenable_professional:*:*:*:*:*:*:*:*
EPSS
Процентиль: 88%
0.04056
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to create or rename arbitrary mail directories via the mailbox name argument of the (1) create or (2) rename commands.
EPSS
Процентиль: 88%
0.04056
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other