Arbitrary File Movement Vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2

Arbitrary File Movement Vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2

CVE-2005-1491 · MEDIUM Severity

AV:L/AC:L/AU:N/C:P/I:P/A:P

Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to (1) move their home directory via viewaction.html or (2) move arbitrary files via the importfile parameter to importaction.html.

Learn more about our Web App Pen Testing.