IceWarp Web Mail Multiple Vulnerabilities
Medium Nessus Network Monitor Plugin ID 3248
SynopsisIt is possible to retrieve or delete local files on the remote system through the WebMail.
DescriptionThe remote host is running IceWarp Web Mail, a webmail solution available for the Microsoft Windows platform. The remote version of this software is vulnerable to a Directory Traversal vulnerability that may allow an attacker to retrieve arbitrary files on the system. Another input validation flaw allows an attacker to delete arbitrary files on the remote host. In addition, the existence of these two flaws indicates that IceWarp is vulnerable to cross-site scripting attack.
SolutionNo solution is known at this time.