Back to Database
Status published
Medium
CVE-2004-1721
The (1) function.php or (2) function.view.php scripts in Merak Mail...
Vulnerability Description
The (1) function.php or (2) function.view.php scripts in Merak Mail Server 5.2.7 allow remote attackers to read arbitrary PHP files via a direct HTTP request to port 32000.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-1721
Credits & Attribution
No credits recorded in the NVD database.
References
- http://packetstormsecurity.nl/0408-exploits/merak527.txt
- http://www.osvdb.org/9045
- http://www.securityfocus.com/bid/10966
- http://securitytracker.com/id?1010969
- http://marc.info/?l=bugtraq&m=109279057326044&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17029
- http://secunia.com/advisories/12269
More from merak
View All →CVE-2009-0350
Stack-based buffer overflow in Merak Media Player 3.2 allows remote...
Critical
9.3
CVE-2008-0218
Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail...
Medium
4.3
CVE-2004-1722
SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7...
High
7.5
CVE-2004-1720
The (1) address.html and possibly (2) calendar.html pages in Merak...
Medium
5
CVE-2004-1719
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7...
Medium
4.3
Affected Vendor
merak
View all reports →Affected Software
mail server
Vulnerable Versions:
5.2.7
Timeline
Official Publish:
February 26th, 2005
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.