IceWarp Web Mail Multiple Flaws (3)

This script is Copyright (C) 2005-2011 Tenable Network Security, Inc.


Synopsis :

The remote web server is running a webmail application that is
affected by multiple vulnerabilities.

Description :

The remote host is running IceWarp Web Mail - a webmail solution
available for the Microsoft Windows platform.

The remote version of this software is vulnerable to multiple
input validation issues that could allow an attacker to compromise the
integrity of the remote host.

See also :

http://www.securityfocus.com/archive/1/388751/30/0/threaded

Solution :

Upgrade to IceWarp Web Mail 5.3.3 or newer.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS Temporal Score : 4.3
(CVSS2#E:H/RL:OF/RC:C)
Public Exploit Available : true

Family: CGI abuses

Nessus Plugin ID: 16273 (icewarp_webmail_vulns3.nasl)

Bugtraq ID: 12396

CVE ID: CVE-2005-0320
CVE-2005-0321