Vulnerability Details CVE-2004-2458
Open WebMail 2.30 and earlier, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which allows remote attackers to create arbitrary directories.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 56.3%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2004-2458
-
cpe:2.3:a:open_webmail:open_webmail:1.7
-
cpe:2.3:a:open_webmail:open_webmail:1.71
-
cpe:2.3:a:open_webmail:open_webmail:1.8
-
cpe:2.3:a:open_webmail:open_webmail:1.81
-
cpe:2.3:a:open_webmail:open_webmail:1.90
-
cpe:2.3:a:open_webmail:open_webmail:2.30