CVE-2004-2572
AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters such as "()" or (2) a large number of characters in the Lookup field on the netaddressbook.php web form, which reveals the path in…
Does this matter?
Lower severity and a low EPSS score (1.70%). Track it; it rarely justifies an emergency change on its own.
Description
AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters such as "()" or (2) a large number of characters in the Lookup field on the netaddressbook.php web form, which reveals the path in an ldaplib.php error message when the ldap_search function fails, due to improper processing of the $keyword variable.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.70% probability · 76th percentile
- CISA KEV
- Not listed
- Affected
- amax information technologies/magic winmail server
- Source
- cve@mitre.org
References
- http://members.lycos.co.uk/r34ct/main/ldaplib/ldaplib.php%20reveal%20local%20path%20of%20Winmail%203.6%20webmail%20directory.txtExploit
- http://secunia.com/advisories/11015Vendor Advisory
- http://www.magicwinmail.net/download/english-help.chm
- http://www.osvdb.org/4118Exploit
- http://www.securityfocus.com/bid/9786
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15361
- http://members.lycos.co.uk/r34ct/main/ldaplib/ldaplib.php%20reveal%20local%20path%20of%20Winmail%203.6%20webmail%20directory.txtExploit
- http://secunia.com/advisories/11015Vendor Advisory
- http://www.magicwinmail.net/download/english-help.chm
- http://www.osvdb.org/4118Exploit
- http://www.securityfocus.com/bid/9786
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15361
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.