Null Byte Injection Vulnerability in SmarterTools SmarterMail

Null Byte Injection Vulnerability in SmarterTools SmarterMail

CVE-2004-2584 · MEDIUM Severity

AV:N/AC:L/AU:S/C:N/I:P/A:N

frmAddfolder.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote authenticated users to create a folder that SmarterMail cannot delete or rename via a folder name with a null byte ("%00"). NOTE: it is not clear whether this issue poses a vulnerability.

Learn more about our User Device Pen Test.