4.3

CVE-2009-1467

Exploit

Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the body of a message, related to the email view and incorrect HTML filtering in the cleanHTML function in server/inc/tools.php; or the (2) title, (3) link, or (4) description element in an RSS feed, related to the getHTML function in server/inc/rss/item.php.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IcewarpEmail Server Version <= 9.3.0
IcewarpEmail Server Version2.10.105
IcewarpEmail Server Version2.10.110
IcewarpEmail Server Version2.10.115
IcewarpEmail Server Version2.10.140
IcewarpEmail Server Version2.10.150
IcewarpEmail Server Version2.10.165
IcewarpEmail Server Version2.10.170
IcewarpEmail Server Version2.10.190
IcewarpEmail Server Version2.10.200
IcewarpEmail Server Version2.10.210
IcewarpEmail Server Version2.10.220
IcewarpEmail Server Version2.10.240
IcewarpEmail Server Version2.10.250
IcewarpEmail Server Version2.10.260
IcewarpEmail Server Version2.10.280
IcewarpEmail Server Version2.10.290
IcewarpEmail Server Version2.10.310
IcewarpEmail Server Version2.10.320
IcewarpEmail Server Version2.10.330
IcewarpEmail Server Version2.10.331
IcewarpEmail Server Version2.10.340
IcewarpEmail Server Version2.10.350
IcewarpEmail Server Version2.10.360
IcewarpEmail Server Version3.00.100
IcewarpEmail Server Version3.00.110
IcewarpEmail Server Version3.00.120
IcewarpEmail Server Version3.00.130
IcewarpEmail Server Version3.00.140
IcewarpEmail Server Version3.10.011
IcewarpEmail Server Version3.10.110
IcewarpEmail Server Version4.00.30
IcewarpEmail Server Version4.2.1
IcewarpEmail Server Version4.2.2
IcewarpEmail Server Version4.2.3
IcewarpEmail Server Version4.4.1
IcewarpEmail Server Version4.4.2
IcewarpEmail Server Version4.10.040
IcewarpEmail Server Version4.10.050
IcewarpEmail Server Version5.1.2
IcewarpEmail Server Version5.1.3
IcewarpEmail Server Version5.1.5
IcewarpEmail Server Version5.3.0
IcewarpEmail Server Version5.3.2
IcewarpEmail Server Version5.4.1
IcewarpEmail Server Version5.4.2
IcewarpEmail Server Version5.4.3
IcewarpEmail Server Version5.4.4
IcewarpEmail Server Version5.5.3
IcewarpEmail Server Version5.5.4
IcewarpEmail Server Version5.5.5
IcewarpEmail Server Version5.5.6
IcewarpEmail Server Version5.5.7
IcewarpEmail Server Version5.7.3
IcewarpEmail Server Version5.8.2
IcewarpEmail Server Version5.8.3
IcewarpEmail Server Version5.8.4
IcewarpEmail Server Version5.8.5
IcewarpEmail Server Version5.8.6
IcewarpEmail Server Version5.9.4
IcewarpEmail Server Version6.0.2
IcewarpEmail Server Version6.0.3
IcewarpEmail Server Version6.0.5
IcewarpEmail Server Version6.0.7
IcewarpEmail Server Version6.1.0
IcewarpEmail Server Version6.2.1
IcewarpEmail Server Version7.0.1
IcewarpEmail Server Version7.1.4
IcewarpEmail Server Version7.1.6
IcewarpEmail Server Version7.2.0
IcewarpEmail Server Version7.4.0
IcewarpEmail Server Version7.4.2
IcewarpEmail Server Version7.4.5
IcewarpEmail Server Version7.5.2
IcewarpEmail Server Version7.6.0
IcewarpEmail Server Version7.6.4
IcewarpEmail Server Version8.0.1
IcewarpEmail Server Version8.0.2
IcewarpEmail Server Version8.0.3
IcewarpEmail Server Version8.2.0
IcewarpEmail Server Version8.2.2
IcewarpEmail Server Version8.3.5
IcewarpEmail Server Version8.3.8
IcewarpEmail Server Version8.5.0
IcewarpEmail Server Version8.9.1
IcewarpEmail Server Version9.0.0
IcewarpEmail Server Version9.1.0
IcewarpEmail Server Version9.2.0
IcewarpWebmail Server Version <= 9.3.0
IcewarpWebmail Server Version2.10.105
IcewarpWebmail Server Version2.10.110
IcewarpWebmail Server Version2.10.115
IcewarpWebmail Server Version2.10.140
IcewarpWebmail Server Version2.10.150
IcewarpWebmail Server Version2.10.165
IcewarpWebmail Server Version2.10.170
IcewarpWebmail Server Version2.10.190
IcewarpWebmail Server Version2.10.200
IcewarpWebmail Server Version2.10.210
IcewarpWebmail Server Version2.10.220
IcewarpWebmail Server Version2.10.240
IcewarpWebmail Server Version2.10.250
IcewarpWebmail Server Version2.10.260
IcewarpWebmail Server Version2.10.280
IcewarpWebmail Server Version2.10.290
IcewarpWebmail Server Version2.10.310
IcewarpWebmail Server Version2.10.320
IcewarpWebmail Server Version2.10.330
IcewarpWebmail Server Version2.10.331
IcewarpWebmail Server Version2.10.340
IcewarpWebmail Server Version2.10.350
IcewarpWebmail Server Version2.10.360
IcewarpWebmail Server Version3.00.100
IcewarpWebmail Server Version3.00.110
IcewarpWebmail Server Version3.00.120
IcewarpWebmail Server Version3.00.130
IcewarpWebmail Server Version3.00.140
IcewarpWebmail Server Version3.10.011
IcewarpWebmail Server Version3.10.110
IcewarpWebmail Server Version4.00.30
IcewarpWebmail Server Version4.2.1
IcewarpWebmail Server Version4.2.2
IcewarpWebmail Server Version4.2.3
IcewarpWebmail Server Version4.4.1
IcewarpWebmail Server Version4.4.2
IcewarpWebmail Server Version4.10.040
IcewarpWebmail Server Version4.10.050
IcewarpWebmail Server Version5.1.2
IcewarpWebmail Server Version5.1.3
IcewarpWebmail Server Version5.1.5
IcewarpWebmail Server Version5.3.0
IcewarpWebmail Server Version5.3.2
IcewarpWebmail Server Version5.4.1
IcewarpWebmail Server Version5.4.2
IcewarpWebmail Server Version5.4.3
IcewarpWebmail Server Version5.4.4
IcewarpWebmail Server Version5.5.3
IcewarpWebmail Server Version5.5.4
IcewarpWebmail Server Version5.5.5
IcewarpWebmail Server Version5.5.6
IcewarpWebmail Server Version5.5.7
IcewarpWebmail Server Version5.7.3
IcewarpWebmail Server Version5.8.2
IcewarpWebmail Server Version5.8.3
IcewarpWebmail Server Version5.8.4
IcewarpWebmail Server Version5.8.5
IcewarpWebmail Server Version5.8.6
IcewarpWebmail Server Version5.9.4
IcewarpWebmail Server Version6.0.2
IcewarpWebmail Server Version6.0.3
IcewarpWebmail Server Version6.0.5
IcewarpWebmail Server Version6.0.7
IcewarpWebmail Server Version6.1.0
IcewarpWebmail Server Version6.2.1
IcewarpWebmail Server Version7.0.1
IcewarpWebmail Server Version7.1.4
IcewarpWebmail Server Version7.1.6
IcewarpWebmail Server Version7.2.0
IcewarpWebmail Server Version7.4.0
IcewarpWebmail Server Version7.4.2
IcewarpWebmail Server Version7.4.5
IcewarpWebmail Server Version7.5.2
IcewarpWebmail Server Version7.6.0
IcewarpWebmail Server Version7.6.4
IcewarpWebmail Server Version8.0.1
IcewarpWebmail Server Version8.0.2
IcewarpWebmail Server Version8.0.3
IcewarpWebmail Server Version8.2.0
IcewarpWebmail Server Version8.2.2
IcewarpWebmail Server Version8.3.5
IcewarpWebmail Server Version8.3.8
IcewarpWebmail Server Version8.5.0
IcewarpWebmail Server Version8.9.1
IcewarpWebmail Server Version9.0.0
IcewarpWebmail Server Version9.1.0
IcewarpWebmail Server Version9.2.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.2% 0.912
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.