Null Byte Injection Vulnerability in SmarterMail by SmarterTools
CVE-2004-2584
Currently unrated
What is CVE-2004-2584?
The frmAddfolder.aspx component in SmarterTools' SmarterMail versions 1.6.1511 and 1.6.1529 is susceptible to a null byte injection flaw. This vulnerability allows remote authenticated users to create folders with names that contain a null byte ('%00'), resulting in folders that cannot be deleted or renamed by the software. The implications of this issue may affect folder management within the application, causing potential disruption for users.
References
Timeline
Vulnerability Reserved
Vulnerability published