{"api_version":"1","generated_at":"2026-07-23T07:16:06+00:00","cve":"CVE-2004-1103","urls":{"html":"https://cve.report/CVE-2004-1103","api":"https://cve.report/api/cve/CVE-2004-1103.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1103","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1103"},"summary":{"title":"CVE-2004-1103","description":"MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to gain sensitive information via the debug parameter, which reveals information such as the path to the web root and the web server version.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-01-10 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.kb.cert.org/vuls/id/858726","name":"http://www.kb.cert.org/vuls/id/858726","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Vulnerability Note VU#858726","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.procheckup.com/security_info/vuln_pr0409.html","name":"http://www.procheckup.com/security_info/vuln_pr0409.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ProCheckUp - 2005","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/11595","name":"http://www.securityfocus.com/bid/11595","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"TIPS MailPost Remote Debug Mode Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17952","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17952","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1103","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1103","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1103","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tips","cpe5":"mailpost","cpe6":"5.1.1_sv","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:39:00.902Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"mailpost-information-disclosure(17952)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17952"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.procheckup.com/security_info/vuln_pr0409.html"},{"name":"11595","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11595"},{"name":"VU#858726","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/858726"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-11-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to gain sensitive information via the debug parameter, which reveals information such as the path to the web root and the web server version."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"mailpost-information-disclosure(17952)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17952"},{"tags":["x_refsource_MISC"],"url":"http://www.procheckup.com/security_info/vuln_pr0409.html"},{"name":"11595","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11595"},{"name":"VU#858726","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/858726"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1103","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to gain sensitive information via the debug parameter, which reveals information such as the path to the web root and the web server version."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"mailpost-information-disclosure(17952)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17952"},{"name":"http://www.procheckup.com/security_info/vuln_pr0409.html","refsource":"MISC","url":"http://www.procheckup.com/security_info/vuln_pr0409.html"},{"name":"11595","refsource":"BID","url":"http://www.securityfocus.com/bid/11595"},{"name":"VU#858726","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/858726"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1103","datePublished":"2004-12-01T05:00:00.000Z","dateReserved":"2004-11-30T00:00:00.000Z","dateUpdated":"2024-08-08T00:39:00.902Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-01-10 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:tips:mailpost:5.1.1_sv:*:*:*:*:*:*:*","matchCriteriaId":"7C151C86-140B-44E1-8F14-693AF08227E3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1103","Ordinal":"1","Title":"CVE-2004-1103","CVE":"CVE-2004-1103","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1103","Ordinal":"1","NoteData":"MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to gain sensitive information via the debug parameter, which reveals information such as the path to the web root and the web server version.","Type":"Description","Title":"CVE-2004-1103"},{"CveYear":"2004","CveId":"1103","Ordinal":"2","NoteData":"2004-12-01","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1103","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}