CVE-2004-2071
Description
Macallan Mail Solution 2.8.4.6 (Build 260) and earlier allows remote attackers to bypass web interface authentication by sending an HTTP GET request with two slashes after the server name.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Macallan Mail Solution 2.8.4.6 (Build 260) and earlier allows remote attackers to bypass web interface authentication by sending an HTTP GET request with two slashes after the server name.
Vulnerability
The vulnerability exists in Macallan Mail Solution version 2.8.4.6 (Build 260) and possibly earlier versions. The authentication bypass occurs in the web interface when a remote attacker sends an HTTP GET request that includes two slashes ("//") immediately after the server name. This malformed request bypasses the authentication mechanism and grants unauthorized access to the administrative web interface [1].
Exploitation
An attacker can exploit this vulnerability by simply sending a crafted HTTP GET request to the affected server. No authentication, user interaction, or special network position is required beyond the ability to send HTTP requests to the web interface. The attacker must include two slashes ("//") after the server name in the request URI. For example, requesting http://target//admin instead of http://target/admin may trigger the bypass [1].
Impact
Successful exploitation allows a remote, unauthenticated attacker to bypass authentication and gain access to the administrative web interface of Macallan Mail Solution. This could lead to full compromise of the mail server, including reading, modifying, or deleting emails and user accounts, as well as potentially further network penetration from the compromised server [1].
Mitigation
No official patch or fixed version has been identified in the available references. The vendor is likely no longer supporting this product. Users should consider upgrading to a supported mail solution or restricting network access to the web interface (e.g., via firewall rules or VPN) as a workaround. This CVE is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog [1].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2cpe:2.3:a:macallan:mail_solution:2.8.4.6_build_260:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:macallan:mail_solution:2.8.4.6_build_260:*:*:*:*:*:*:*
- (no CPE)range: <=2.8.4.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6News mentions
0No linked articles in our index yet.