IceWarp Web Mail Multiple Vulnerabilities

Medium Nessus Network Monitor Plugin ID 3248

Synopsis

It is possible to retrieve or delete local files on the remote system through the WebMail.

Description

The remote host is running IceWarp Web Mail, a webmail solution available for the Microsoft Windows platform. The remote version of this software is vulnerable to a Directory Traversal vulnerability that may allow an attacker to retrieve arbitrary files on the system. Another input validation flaw allows an attacker to delete arbitrary files on the remote host. In addition, the existence of these two flaws indicates that IceWarp is vulnerable to cross-site scripting attack.

Solution

No solution is known at this time.

Plugin Details

Severity: Medium

ID: 3248

Family: CGI

Published: 2005/10/03

Modified: 2016/02/05

Dependencies: 1442

Nessus ID: 19782

Risk Information

Risk Factor: Medium

CVSSv2

Base Score: 6.4

Temporal Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

Temporal Vector: CVSS2#E:H/RL:U/RC:ND

CVSSv3

Base Score: 6.4

Temporal Score: 6.4

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Temporal Vector: CVSS3#E:H/RL:U/RC:X

Reference Information

CVE: CVE-2005-3133, CVE-2005-3131

BID: 14988, 14986, 14980