IceWarp Merak WebMail Server < 9.4.2 Multiple Vulnerabilities

High Nessus Network Monitor Plugin ID 5019


The remote webmail server is vulnerable to multiple attack vectors.


The remote host is running IcewWarp WebMail Server - a webmail server for Windows and Linux. According to its banner, the version of IceWarp installed on the remote host is earlier 9.4.2. Such versions are reportedly affected by multiple vulnerabilities :

-A SQL injection vulnerability in the search form of the web-based groupware component. (CVE-2009-1468)

-A cross-site scripting vulnerability exists because the application fails to properly sanitize HTML emails. An attacker can exploit this flaw through the 'cleanHTML()' function of the 'html/webmail/server/inc/tools.php' script. (CVE-2009-1467)

- A cross site-scripting vulnerability exists because the applciation fails to properly sanitize RSS feeds. An attacker can exploit this flaw through the 'cleanHTML()' function of the 'html/webmail/server/inc/rss/rss.php' script. (CVE-2009-1467)

- An input validation flaw in the 'Forgot Password' function on the login page. (CVE-2009-1469)

An attacker could exploit these flaws to steal sensitive information, upload files, or possibly execute arbitrary code subject to the privileges of the affected application.


Upgrading to IceWarp Merak WebMail Server version 9.4.2 or later reportedly resolves the issues.

See Also

Plugin Details

Severity: High

ID: 5019

File Name: 5019.prm

Family: CGI

Published: 2004/08/18

Modified: 2016/01/15

Dependencies: 1442

Risk Information

Risk Factor: High


Base Score: 7.5

Temporal Score: 6.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:F/RL:OF/RC:C


Base Score: 7.3

Temporal Score: 6.8


Temporal Vector: CVSS3#E:F/RL:O/RC:C

Reference Information

CVE: CVE-2009-1467, CVE-2009-1468, CVE-2009-1469

BID: 34820, 34823, 34825, 34827