frmAddfolder.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote authenticated users to create a folder that SmarterMail cannot delete or rename via a folder name with a null byte ("%00"). NOTE: it is not clear whether this issue poses a vulnerability.
| Software | From | Fixed in |
|---|---|---|
| smartertools / smartermail | 1.6.1511 | 1.6.1511.x |
| smartertools / smartermail | 1.6.1529 | 1.6.1529.x |