CVE-2005-3691
Description
Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to create or rename arbitrary mail directories via the mailbox name argument of the (1) create or (2) rename commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Directory traversal in MailEnable IMAP service allows remote attackers to create or rename arbitrary mail directories.
Vulnerability
Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier. The bug resides in the handling of the mailbox name argument for the create and rename commands, allowing an attacker to traverse directories by including path traversal sequences (e.g., ../) in the mailbox name [1].
Exploitation
An attacker can exploit this vulnerability by connecting to the IMAP service and issuing a create or rename command with a crafted mailbox name containing directory traversal sequences. No authentication is required other than being able to connect to the IMAP service (typically on port 143). The attacker can specify a path that escapes the intended mail directory and points to any location on the filesystem that the mail service process has write access to [1].
Impact
Successful exploitation allows a remote attacker to create or rename arbitrary directories on the server. This could lead to unauthorized file system manipulation, potentially affecting mail storage, configuration, or other services. The exact impact depends on the permissions of the mail service process; however, it does not directly provide code execution but can enable further attacks such as placing malicious files in sensitive locations [1].
Mitigation
MailEnable has released hot fixes to address this vulnerability. Users are advised to install the latest hot fixes from the MailEnable hot fix download page [1]. It is also recommended to upgrade to the most recent version of MailEnable, which includes all past hot fixes. If immediate patching is not possible, restricting access to the IMAP service via firewall rules or network segmentation may reduce exposure.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.1
- Range: <=1.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- secunia.com/advisories/17633nvdPatchVendor Advisory
- secunia.com/secunia_research/2005-59/advisory/nvdPatchVendor Advisory
- www.mailenable.com/hotfix/nvdPatch
- securitytracker.com/idnvd
- www.securityfocus.com/bid/15494nvd
- www.vupen.com/english/advisories/2005/2484nvd
News mentions
0No linked articles in our index yet.