CVE-2005-3133 describes multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r and Icewarp Web Mail 5.5.1, and potentially earlier versions. These flaws allow remote attackers to either delete arbitrary files or directories via a relative path in the 'id' parameter to logout.html, or include arbitrary PHP or other files using the 'helpid' parameter to help.html. The vulnerability has a CVSS score of 5.0, indicating a medium severity, with low attack complexity and no authentication required, primarily impacting integrity. While there is no evidence of active exploitation or inclusion in CISA's KEV catalog, an exploit for arbitrary file deletion is available on ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.5.1CPE matchmatch criteria | cpe:2.3:a:icewarp:web_mail:5.5.1:*:*:*:*:*:*:* | ||
8.2.4rCPE matchmatch criteria | cpe:2.3:a:merak:mail_server:8.2.4r:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.