6.5

CVE-2009-1468

Exploit

Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) sql and (2) order_by elements in an XML search query.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IcewarpEmail Server Version <= 9.3.0
IcewarpEmail Server Version2.10.105
IcewarpEmail Server Version2.10.110
IcewarpEmail Server Version2.10.115
IcewarpEmail Server Version2.10.140
IcewarpEmail Server Version2.10.150
IcewarpEmail Server Version2.10.165
IcewarpEmail Server Version2.10.170
IcewarpEmail Server Version2.10.190
IcewarpEmail Server Version2.10.200
IcewarpEmail Server Version2.10.210
IcewarpEmail Server Version2.10.220
IcewarpEmail Server Version2.10.240
IcewarpEmail Server Version2.10.250
IcewarpEmail Server Version2.10.260
IcewarpEmail Server Version2.10.280
IcewarpEmail Server Version2.10.290
IcewarpEmail Server Version2.10.310
IcewarpEmail Server Version2.10.320
IcewarpEmail Server Version2.10.330
IcewarpEmail Server Version2.10.331
IcewarpEmail Server Version2.10.340
IcewarpEmail Server Version2.10.350
IcewarpEmail Server Version2.10.360
IcewarpEmail Server Version3.00.100
IcewarpEmail Server Version3.00.110
IcewarpEmail Server Version3.00.120
IcewarpEmail Server Version3.00.130
IcewarpEmail Server Version3.00.140
IcewarpEmail Server Version3.10.011
IcewarpEmail Server Version3.10.110
IcewarpEmail Server Version4.00.30
IcewarpEmail Server Version4.2.1
IcewarpEmail Server Version4.2.2
IcewarpEmail Server Version4.2.3
IcewarpEmail Server Version4.4.1
IcewarpEmail Server Version4.4.2
IcewarpEmail Server Version4.10.040
IcewarpEmail Server Version4.10.050
IcewarpEmail Server Version5.1.2
IcewarpEmail Server Version5.1.3
IcewarpEmail Server Version5.1.5
IcewarpEmail Server Version5.3.0
IcewarpEmail Server Version5.3.2
IcewarpEmail Server Version5.4.1
IcewarpEmail Server Version5.4.2
IcewarpEmail Server Version5.4.3
IcewarpEmail Server Version5.4.4
IcewarpEmail Server Version5.5.3
IcewarpEmail Server Version5.5.4
IcewarpEmail Server Version5.5.5
IcewarpEmail Server Version5.5.6
IcewarpEmail Server Version5.5.7
IcewarpEmail Server Version5.7.3
IcewarpEmail Server Version5.8.2
IcewarpEmail Server Version5.8.3
IcewarpEmail Server Version5.8.4
IcewarpEmail Server Version5.8.5
IcewarpEmail Server Version5.8.6
IcewarpEmail Server Version5.9.4
IcewarpEmail Server Version6.0.2
IcewarpEmail Server Version6.0.3
IcewarpEmail Server Version6.0.5
IcewarpEmail Server Version6.0.7
IcewarpEmail Server Version6.1.0
IcewarpEmail Server Version6.2.1
IcewarpEmail Server Version7.0.1
IcewarpEmail Server Version7.1.4
IcewarpEmail Server Version7.1.6
IcewarpEmail Server Version7.2.0
IcewarpEmail Server Version7.4.0
IcewarpEmail Server Version7.4.2
IcewarpEmail Server Version7.4.5
IcewarpEmail Server Version7.5.2
IcewarpEmail Server Version7.6.0
IcewarpEmail Server Version7.6.4
IcewarpEmail Server Version8.0.1
IcewarpEmail Server Version8.0.2
IcewarpEmail Server Version8.0.3
IcewarpEmail Server Version8.2.0
IcewarpEmail Server Version8.2.2
IcewarpEmail Server Version8.3.5
IcewarpEmail Server Version8.3.8
IcewarpEmail Server Version8.5.0
IcewarpEmail Server Version8.9.1
IcewarpEmail Server Version9.0.0
IcewarpEmail Server Version9.1.0
IcewarpEmail Server Version9.2.0
IcewarpWebmail Server Version <= 9.3.0
IcewarpWebmail Server Version2.10.105
IcewarpWebmail Server Version2.10.110
IcewarpWebmail Server Version2.10.115
IcewarpWebmail Server Version2.10.140
IcewarpWebmail Server Version2.10.150
IcewarpWebmail Server Version2.10.165
IcewarpWebmail Server Version2.10.170
IcewarpWebmail Server Version2.10.190
IcewarpWebmail Server Version2.10.200
IcewarpWebmail Server Version2.10.210
IcewarpWebmail Server Version2.10.220
IcewarpWebmail Server Version2.10.240
IcewarpWebmail Server Version2.10.250
IcewarpWebmail Server Version2.10.260
IcewarpWebmail Server Version2.10.280
IcewarpWebmail Server Version2.10.290
IcewarpWebmail Server Version2.10.310
IcewarpWebmail Server Version2.10.320
IcewarpWebmail Server Version2.10.330
IcewarpWebmail Server Version2.10.331
IcewarpWebmail Server Version2.10.340
IcewarpWebmail Server Version2.10.350
IcewarpWebmail Server Version2.10.360
IcewarpWebmail Server Version3.00.100
IcewarpWebmail Server Version3.00.110
IcewarpWebmail Server Version3.00.120
IcewarpWebmail Server Version3.00.130
IcewarpWebmail Server Version3.00.140
IcewarpWebmail Server Version3.10.011
IcewarpWebmail Server Version3.10.110
IcewarpWebmail Server Version4.00.30
IcewarpWebmail Server Version4.2.1
IcewarpWebmail Server Version4.2.2
IcewarpWebmail Server Version4.2.3
IcewarpWebmail Server Version4.4.1
IcewarpWebmail Server Version4.4.2
IcewarpWebmail Server Version4.10.040
IcewarpWebmail Server Version4.10.050
IcewarpWebmail Server Version5.1.2
IcewarpWebmail Server Version5.1.3
IcewarpWebmail Server Version5.1.5
IcewarpWebmail Server Version5.3.0
IcewarpWebmail Server Version5.3.2
IcewarpWebmail Server Version5.4.1
IcewarpWebmail Server Version5.4.2
IcewarpWebmail Server Version5.4.3
IcewarpWebmail Server Version5.4.4
IcewarpWebmail Server Version5.5.3
IcewarpWebmail Server Version5.5.4
IcewarpWebmail Server Version5.5.5
IcewarpWebmail Server Version5.5.6
IcewarpWebmail Server Version5.5.7
IcewarpWebmail Server Version5.7.3
IcewarpWebmail Server Version5.8.2
IcewarpWebmail Server Version5.8.3
IcewarpWebmail Server Version5.8.4
IcewarpWebmail Server Version5.8.5
IcewarpWebmail Server Version5.8.6
IcewarpWebmail Server Version5.9.4
IcewarpWebmail Server Version6.0.2
IcewarpWebmail Server Version6.0.3
IcewarpWebmail Server Version6.0.5
IcewarpWebmail Server Version6.0.7
IcewarpWebmail Server Version6.1.0
IcewarpWebmail Server Version6.2.1
IcewarpWebmail Server Version7.0.1
IcewarpWebmail Server Version7.1.4
IcewarpWebmail Server Version7.1.6
IcewarpWebmail Server Version7.2.0
IcewarpWebmail Server Version7.4.0
IcewarpWebmail Server Version7.4.2
IcewarpWebmail Server Version7.4.5
IcewarpWebmail Server Version7.5.2
IcewarpWebmail Server Version7.6.0
IcewarpWebmail Server Version7.6.4
IcewarpWebmail Server Version8.0.1
IcewarpWebmail Server Version8.0.2
IcewarpWebmail Server Version8.0.3
IcewarpWebmail Server Version8.2.0
IcewarpWebmail Server Version8.2.2
IcewarpWebmail Server Version8.3.5
IcewarpWebmail Server Version8.3.8
IcewarpWebmail Server Version8.5.0
IcewarpWebmail Server Version8.9.1
IcewarpWebmail Server Version9.0.0
IcewarpWebmail Server Version9.1.0
IcewarpWebmail Server Version9.2.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.523
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.