Icewarp

Mail Server

19 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.28%
  • Published 06.01.2020 01:15:10
  • Last modified 21.11.2024 04:34:27

IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in notes for contacts.

Exploit
  • EPSS 0.3%
  • Published 06.01.2020 00:15:10
  • Last modified 21.11.2024 04:34:27

IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for objects.

Exploit
  • EPSS 75.9%
  • Published 03.06.2019 17:29:01
  • Last modified 21.11.2024 04:23:09

IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.

Exploit
  • EPSS 0.35%
  • Published 01.09.2018 18:29:01
  • Last modified 21.11.2024 03:52:31

In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field.

Exploit
  • EPSS 0.33%
  • Published 30.06.2018 14:29:00
  • Last modified 21.11.2024 04:12:12

Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers to inject arbitrary web script or HTML.

Exploit
  • EPSS 91.76%
  • Published 08.05.2018 20:29:00
  • Last modified 21.11.2024 02:25:34

Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash...

Exploit
  • EPSS 0.18%
  • Published 23.08.2017 14:29:00
  • Last modified 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in the admin panel in IceWarp Mail Server 10.4.4 allows remote authenticated domain administrators to inject arbitrary web script or HTML via a crafted user name.

Exploit
  • EPSS 8.55%
  • Published 30.09.2011 17:55:01
  • Last modified 11.04.2025 00:51:21

server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML exte...

Exploit
  • EPSS 0.4%
  • Published 30.09.2011 17:55:01
  • Last modified 11.04.2025 00:51:21

IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to obtain configuration information via a direct request to the /server URI, which triggers a call to the phpinfo function.