{"api_version":"1","generated_at":"2026-07-23T11:20:59+00:00","cve":"CVE-2005-3691","urls":{"html":"https://cve.report/CVE-2005-3691","api":"https://cve.report/api/cve/CVE-2005-3691.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3691","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3691"},"summary":{"title":"CVE-2005-3691","description":"Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to create or rename arbitrary mail directories via the mailbox name argument of the (1) create or (2) rename commands.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-11-19 01:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://securitytracker.com/id?1015239","name":"http://securitytracker.com/id?1015239","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - MailEnable Bugs Let Remote Authenticated Users Execute Arbitrary Code and Create/Delete Directories on the Target System.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/17633","name":"http://secunia.com/advisories/17633","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - MailEnable Buffer Overflow and Directory Traversal Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mailenable.com/hotfix/","name":"http://www.mailenable.com/hotfix/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"MailEnable™ - Hot Fixes Download Page","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/secunia_research/2005-59/advisory/","name":"http://secunia.com/secunia_research/2005-59/advisory/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15494","name":"http://www.securityfocus.com/bid/15494","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"MailEnable IMAP Command Directory Traversal Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2005/2484","name":"http://www.vupen.com/english/advisories/2005/2484","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3691","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3691","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3691","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mailenable","cpe5":"mailenable_enterprise","cpe6":"1.00","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3691","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mailenable","cpe5":"mailenable_enterprise","cpe6":"1.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3691","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mailenable","cpe5":"mailenable_enterprise","cpe6":"1.02","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3691","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mailenable","cpe5":"mailenable_enterprise","cpe6":"1.03","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3691","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mailenable","cpe5":"mailenable_enterprise","cpe6":"1.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3691","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mailenable","cpe5":"mailenable_enterprise","cpe6":"1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3691","vulnerable":"0","versionEndIncluding":"1.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mailenable","cpe5":"mailenable_professional","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:17:23.630Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"17633","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17633"},{"name":"ADV-2005-2484","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2484"},{"name":"15494","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15494"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2005-59/advisory/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mailenable.com/hotfix/"},{"name":"1015239","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015239"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-11-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to create or rename arbitrary mail directories via the mailbox name argument of the (1) create or (2) rename commands."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-11-24T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"17633","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17633"},{"name":"ADV-2005-2484","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2484"},{"name":"15494","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15494"},{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2005-59/advisory/"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mailenable.com/hotfix/"},{"name":"1015239","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015239"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3691","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to create or rename arbitrary mail directories via the mailbox name argument of the (1) create or (2) rename commands."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"17633","refsource":"SECUNIA","url":"http://secunia.com/advisories/17633"},{"name":"ADV-2005-2484","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2484"},{"name":"15494","refsource":"BID","url":"http://www.securityfocus.com/bid/15494"},{"name":"http://secunia.com/secunia_research/2005-59/advisory/","refsource":"MISC","url":"http://secunia.com/secunia_research/2005-59/advisory/"},{"name":"http://www.mailenable.com/hotfix/","refsource":"CONFIRM","url":"http://www.mailenable.com/hotfix/"},{"name":"1015239","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015239"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3691","datePublished":"2005-11-19T01:00:00.000Z","dateReserved":"2005-11-19T00:00:00.000Z","dateUpdated":"2024-08-07T23:17:23.630Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-11-19 01:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:mailenable:mailenable_enterprise:1.00:*:*:*:*:*:*:*","matchCriteriaId":"FCAA0B95-5875-41CF-90BA-EF07D240FF08"},{"vulnerable":false,"criteria":"cpe:2.3:a:mailenable:mailenable_enterprise:1.1:*:*:*:*:*:*:*","matchCriteriaId":"45540A37-2CBF-453F-8EFF-696B9318499F"},{"vulnerable":false,"criteria":"cpe:2.3:a:mailenable:mailenable_enterprise:1.01:*:*:*:*:*:*:*","matchCriteriaId":"724E8638-CF5A-480B-89D7-0E029A0C5965"},{"vulnerable":false,"criteria":"cpe:2.3:a:mailenable:mailenable_enterprise:1.02:*:*:*:*:*:*:*","matchCriteriaId":"48B664B5-EEF9-4C5F-B23C-E4D54DBF2EC5"},{"vulnerable":false,"criteria":"cpe:2.3:a:mailenable:mailenable_enterprise:1.03:*:*:*:*:*:*:*","matchCriteriaId":"E27EEFD5-19B1-4F0C-BD52-257594C37310"},{"vulnerable":false,"criteria":"cpe:2.3:a:mailenable:mailenable_enterprise:1.04:*:*:*:*:*:*:*","matchCriteriaId":"53BB6A16-65D3-43CF-BFB4-E0616476A979"},{"vulnerable":false,"criteria":"cpe:2.3:a:mailenable:mailenable_professional:*:*:*:*:*:*:*:*","versionEndIncluding":"1.6","matchCriteriaId":"4B880760-D0E3-46C6-A12F-3D9A444C92C1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3691","Ordinal":"1","Title":"CVE-2005-3691","CVE":"CVE-2005-3691","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3691","Ordinal":"1","NoteData":"Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to create or rename arbitrary mail directories via the mailbox name argument of the (1) create or (2) rename commands.","Type":"Description","Title":"CVE-2005-3691"},{"CveYear":"2005","CveId":"3691","Ordinal":"2","NoteData":"2005-11-18","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3691","Ordinal":"3","NoteData":"2005-11-24","Type":"Other","Title":"Modified"}]}}}