{"api_version":"1","generated_at":"2026-07-23T10:39:50+00:00","cve":"CVE-2004-1129","urls":{"html":"https://cve.report/CVE-2004-1129","api":"https://cve.report/api/cve/CVE-2004-1129.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1129","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1129"},"summary":{"title":"CVE-2004-1129","description":"SQL injection vulnerability in (1) fdelmail.asp, (2) addressc.asp, and possibly (3) postmail.asp and (4) fmvmail.asp in CMailServer 5.2 allow remote attackers to inject arbitrary SQL commands and delete mail metadata or e-mail addresses of contacts via the indexOfMail parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-01-10 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18281","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18281","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.security.org.sg/vuln/cmailserver52.html","name":"http://www.security.org.sg/vuln/cmailserver52.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SIG^2 G-TEC - CMailServer WebMail v5.2 Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/11742","name":"http://www.securityfocus.com/bid/11742","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Youngzsoft CMailServer Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=110137313329955&w=2","name":"http://marc.info/?l=bugtraq&m=110137313329955&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[SIG^2 G-TEC] CMailServer WebMail v5.2 Multiple Vulnerabilities' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1129","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1129","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1129","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"youngzsoft","cpe5":"cmailserver","cpe6":"5.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:39:00.864Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20041124 [SIG^2 G-TEC] CMailServer WebMail v5.2 Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=110137313329955&w=2"},{"name":"11742","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11742"},{"name":"cmailserver-fdelmail-addressc-sql-injection(18281)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18281"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.security.org.sg/vuln/cmailserver52.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-11-24T00:00:00.000Z","descriptions":[{"lang":"en","value":"SQL injection vulnerability in (1) fdelmail.asp, (2) addressc.asp, and possibly (3) postmail.asp and (4) fmvmail.asp in CMailServer 5.2 allow remote attackers to inject arbitrary SQL commands and delete mail metadata or e-mail addresses of contacts via the indexOfMail parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20041124 [SIG^2 G-TEC] CMailServer WebMail v5.2 Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=110137313329955&w=2"},{"name":"11742","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11742"},{"name":"cmailserver-fdelmail-addressc-sql-injection(18281)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18281"},{"tags":["x_refsource_MISC"],"url":"http://www.security.org.sg/vuln/cmailserver52.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1129","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL injection vulnerability in (1) fdelmail.asp, (2) addressc.asp, and possibly (3) postmail.asp and (4) fmvmail.asp in CMailServer 5.2 allow remote attackers to inject arbitrary SQL commands and delete mail metadata or e-mail addresses of contacts via the indexOfMail parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20041124 [SIG^2 G-TEC] CMailServer WebMail v5.2 Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=110137313329955&w=2"},{"name":"11742","refsource":"BID","url":"http://www.securityfocus.com/bid/11742"},{"name":"cmailserver-fdelmail-addressc-sql-injection(18281)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18281"},{"name":"http://www.security.org.sg/vuln/cmailserver52.html","refsource":"MISC","url":"http://www.security.org.sg/vuln/cmailserver52.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1129","datePublished":"2004-12-05T05:00:00.000Z","dateReserved":"2004-12-02T00:00:00.000Z","dateUpdated":"2024-08-08T00:39:00.864Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-01-10 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:youngzsoft:cmailserver:5.2.0:*:*:*:*:*:*:*","matchCriteriaId":"65706226-7DD3-4F68-9E17-09E086AA7CF8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1129","Ordinal":"1","Title":"CVE-2004-1129","CVE":"CVE-2004-1129","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1129","Ordinal":"1","NoteData":"SQL injection vulnerability in (1) fdelmail.asp, (2) addressc.asp, and possibly (3) postmail.asp and (4) fmvmail.asp in CMailServer 5.2 allow remote attackers to inject arbitrary SQL commands and delete mail metadata or e-mail addresses of contacts via the indexOfMail parameter.","Type":"Description","Title":"CVE-2004-1129"},{"CveYear":"2004","CveId":"1129","Ordinal":"2","NoteData":"2004-12-05","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1129","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}