Unknown vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to obtain the full path of the server via certain requests to (1) calendar_addevent.html, (2) calendar_event.html, or (3) calendar_task.html.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=111530933016434&w=2 | mailing list |
http://secunia.com/advisories/15249 | third party advisory patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/20469 | vdb entry |