4.3

CVE-2009-1469

Exploit
CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server before 9.4.2 makes it easier for remote attackers to trick a user into disclosing credentials via CRLF sequences preceding a Reply-To header in the subject element of an XML document, as demonstrated by triggering an e-mail message from the server that contains a user's correct credentials, and requests that the user compose a reply that includes this message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IcewarpEmail Server Version <= 9.3.0
IcewarpEmail Server Version2.10.105
IcewarpEmail Server Version2.10.110
IcewarpEmail Server Version2.10.115
IcewarpEmail Server Version2.10.140
IcewarpEmail Server Version2.10.150
IcewarpEmail Server Version2.10.165
IcewarpEmail Server Version2.10.170
IcewarpEmail Server Version2.10.190
IcewarpEmail Server Version2.10.200
IcewarpEmail Server Version2.10.210
IcewarpEmail Server Version2.10.220
IcewarpEmail Server Version2.10.240
IcewarpEmail Server Version2.10.250
IcewarpEmail Server Version2.10.260
IcewarpEmail Server Version2.10.280
IcewarpEmail Server Version2.10.290
IcewarpEmail Server Version2.10.310
IcewarpEmail Server Version2.10.320
IcewarpEmail Server Version2.10.330
IcewarpEmail Server Version2.10.331
IcewarpEmail Server Version2.10.340
IcewarpEmail Server Version2.10.350
IcewarpEmail Server Version2.10.360
IcewarpEmail Server Version3.00.100
IcewarpEmail Server Version3.00.110
IcewarpEmail Server Version3.00.120
IcewarpEmail Server Version3.00.130
IcewarpEmail Server Version3.00.140
IcewarpEmail Server Version3.10.011
IcewarpEmail Server Version3.10.110
IcewarpEmail Server Version4.00.30
IcewarpEmail Server Version4.2.1
IcewarpEmail Server Version4.2.2
IcewarpEmail Server Version4.2.3
IcewarpEmail Server Version4.4.1
IcewarpEmail Server Version4.4.2
IcewarpEmail Server Version4.10.040
IcewarpEmail Server Version4.10.050
IcewarpEmail Server Version5.1.2
IcewarpEmail Server Version5.1.3
IcewarpEmail Server Version5.1.5
IcewarpEmail Server Version5.3.0
IcewarpEmail Server Version5.3.2
IcewarpEmail Server Version5.4.1
IcewarpEmail Server Version5.4.2
IcewarpEmail Server Version5.4.3
IcewarpEmail Server Version5.4.4
IcewarpEmail Server Version5.5.3
IcewarpEmail Server Version5.5.4
IcewarpEmail Server Version5.5.5
IcewarpEmail Server Version5.5.6
IcewarpEmail Server Version5.5.7
IcewarpEmail Server Version5.7.3
IcewarpEmail Server Version5.8.2
IcewarpEmail Server Version5.8.3
IcewarpEmail Server Version5.8.4
IcewarpEmail Server Version5.8.5
IcewarpEmail Server Version5.8.6
IcewarpEmail Server Version5.9.4
IcewarpEmail Server Version6.0.2
IcewarpEmail Server Version6.0.3
IcewarpEmail Server Version6.0.5
IcewarpEmail Server Version6.0.7
IcewarpEmail Server Version6.1.0
IcewarpEmail Server Version6.2.1
IcewarpEmail Server Version7.0.1
IcewarpEmail Server Version7.1.4
IcewarpEmail Server Version7.1.6
IcewarpEmail Server Version7.2.0
IcewarpEmail Server Version7.4.0
IcewarpEmail Server Version7.4.2
IcewarpEmail Server Version7.4.5
IcewarpEmail Server Version7.5.2
IcewarpEmail Server Version7.6.0
IcewarpEmail Server Version7.6.4
IcewarpEmail Server Version8.0.1
IcewarpEmail Server Version8.0.2
IcewarpEmail Server Version8.0.3
IcewarpEmail Server Version8.2.0
IcewarpEmail Server Version8.2.2
IcewarpEmail Server Version8.3.5
IcewarpEmail Server Version8.3.8
IcewarpEmail Server Version8.5.0
IcewarpEmail Server Version8.9.1
IcewarpEmail Server Version9.0.0
IcewarpEmail Server Version9.1.0
IcewarpEmail Server Version9.2.0
IcewarpWebmail Server Version <= 9.3.0
IcewarpWebmail Server Version2.10.105
IcewarpWebmail Server Version2.10.110
IcewarpWebmail Server Version2.10.115
IcewarpWebmail Server Version2.10.140
IcewarpWebmail Server Version2.10.150
IcewarpWebmail Server Version2.10.165
IcewarpWebmail Server Version2.10.170
IcewarpWebmail Server Version2.10.190
IcewarpWebmail Server Version2.10.200
IcewarpWebmail Server Version2.10.210
IcewarpWebmail Server Version2.10.220
IcewarpWebmail Server Version2.10.240
IcewarpWebmail Server Version2.10.250
IcewarpWebmail Server Version2.10.260
IcewarpWebmail Server Version2.10.280
IcewarpWebmail Server Version2.10.290
IcewarpWebmail Server Version2.10.310
IcewarpWebmail Server Version2.10.320
IcewarpWebmail Server Version2.10.330
IcewarpWebmail Server Version2.10.331
IcewarpWebmail Server Version2.10.340
IcewarpWebmail Server Version2.10.350
IcewarpWebmail Server Version2.10.360
IcewarpWebmail Server Version3.00.100
IcewarpWebmail Server Version3.00.110
IcewarpWebmail Server Version3.00.120
IcewarpWebmail Server Version3.00.130
IcewarpWebmail Server Version3.00.140
IcewarpWebmail Server Version3.10.011
IcewarpWebmail Server Version3.10.110
IcewarpWebmail Server Version4.00.30
IcewarpWebmail Server Version4.2.1
IcewarpWebmail Server Version4.2.2
IcewarpWebmail Server Version4.2.3
IcewarpWebmail Server Version4.4.1
IcewarpWebmail Server Version4.4.2
IcewarpWebmail Server Version4.10.040
IcewarpWebmail Server Version4.10.050
IcewarpWebmail Server Version5.1.2
IcewarpWebmail Server Version5.1.3
IcewarpWebmail Server Version5.1.5
IcewarpWebmail Server Version5.3.0
IcewarpWebmail Server Version5.3.2
IcewarpWebmail Server Version5.4.1
IcewarpWebmail Server Version5.4.2
IcewarpWebmail Server Version5.4.3
IcewarpWebmail Server Version5.4.4
IcewarpWebmail Server Version5.5.3
IcewarpWebmail Server Version5.5.4
IcewarpWebmail Server Version5.5.5
IcewarpWebmail Server Version5.5.6
IcewarpWebmail Server Version5.5.7
IcewarpWebmail Server Version5.7.3
IcewarpWebmail Server Version5.8.2
IcewarpWebmail Server Version5.8.3
IcewarpWebmail Server Version5.8.4
IcewarpWebmail Server Version5.8.5
IcewarpWebmail Server Version5.8.6
IcewarpWebmail Server Version5.9.4
IcewarpWebmail Server Version6.0.2
IcewarpWebmail Server Version6.0.3
IcewarpWebmail Server Version6.0.5
IcewarpWebmail Server Version6.0.7
IcewarpWebmail Server Version6.1.0
IcewarpWebmail Server Version6.2.1
IcewarpWebmail Server Version7.0.1
IcewarpWebmail Server Version7.1.4
IcewarpWebmail Server Version7.1.6
IcewarpWebmail Server Version7.2.0
IcewarpWebmail Server Version7.4.0
IcewarpWebmail Server Version7.4.2
IcewarpWebmail Server Version7.4.5
IcewarpWebmail Server Version7.5.2
IcewarpWebmail Server Version7.6.0
IcewarpWebmail Server Version7.6.4
IcewarpWebmail Server Version8.0.1
IcewarpWebmail Server Version8.0.2
IcewarpWebmail Server Version8.0.3
IcewarpWebmail Server Version8.2.0
IcewarpWebmail Server Version8.2.2
IcewarpWebmail Server Version8.3.5
IcewarpWebmail Server Version8.3.8
IcewarpWebmail Server Version8.5.0
IcewarpWebmail Server Version8.9.1
IcewarpWebmail Server Version9.0.0
IcewarpWebmail Server Version9.1.0
IcewarpWebmail Server Version9.2.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.49% 0.892
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.