VYPR
Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026

CVE-2004-2071

CVE-2004-2071

Description

Macallan Mail Solution 2.8.4.6 (Build 260) and earlier allows remote attackers to bypass web interface authentication by sending an HTTP GET request with two slashes after the server name.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Macallan Mail Solution 2.8.4.6 (Build 260) and earlier allows remote attackers to bypass web interface authentication by sending an HTTP GET request with two slashes after the server name.

Vulnerability

The vulnerability exists in Macallan Mail Solution version 2.8.4.6 (Build 260) and possibly earlier versions. The authentication bypass occurs in the web interface when a remote attacker sends an HTTP GET request that includes two slashes ("//") immediately after the server name. This malformed request bypasses the authentication mechanism and grants unauthorized access to the administrative web interface [1].

Exploitation

An attacker can exploit this vulnerability by simply sending a crafted HTTP GET request to the affected server. No authentication, user interaction, or special network position is required beyond the ability to send HTTP requests to the web interface. The attacker must include two slashes ("//") after the server name in the request URI. For example, requesting http://target//admin instead of http://target/admin may trigger the bypass [1].

Impact

Successful exploitation allows a remote, unauthenticated attacker to bypass authentication and gain access to the administrative web interface of Macallan Mail Solution. This could lead to full compromise of the mail server, including reading, modifying, or deleting emails and user accounts, as well as potentially further network penetration from the compromised server [1].

Mitigation

No official patch or fixed version has been identified in the available references. The vendor is likely no longer supporting this product. Users should consider upgrading to a supported mail solution or restricting network access to the web interface (e.g., via firewall rules or VPN) as a workaround. This CVE is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:macallan:mail_solution:2.8.4.6_build_260:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:macallan:mail_solution:2.8.4.6_build_260:*:*:*:*:*:*:*
    • (no CPE)range: <=2.8.4.6

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.