attachment.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to view other users' attachments by specifying the username and message ID in an HTTP request.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/17316 | vdb entry |
http://marc.info/?l=bugtraq&m=109483971420067&w=2 | mailing list |
http://secunia.com/advisories/12789 | exploit third party advisory patch vendor advisory |
http://www.securityfocus.com/bid/11371 | vdb entry patch vendor advisory |