CVE-2004-1102 affects MailPost 5.1.1sv and potentially earlier versions, allowing remote attackers to gain sensitive information. The vulnerability stems from differing error messages that reveal whether a requested file exists or not, enabling file enumeration. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) and a FAUCET Risk Score of 94/100, this vulnerability is easily exploitable over the network with low complexity, leading to partial confidentiality impact. While not in the KEV catalog, an ExploitDB entry (EDB-24723) confirms exploit code availability for remote file enumeration, and the CVE has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.1.1_svCPE matchmatch criteria | cpe:2.3:a:tips:mailpost:5.1.1_sv:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.