Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

IceWarp Web Mail Multiple Vulnerabilities

Medium

Synopsis

It is possible to retrieve or delete local files on the remote system through the WebMail.

Description

The remote host is running IceWarp Web Mail, a webmail solution available for the Microsoft Windows platform. The remote version of this software is vulnerable to a Directory Traversal vulnerability that may allow an attacker to retrieve arbitrary files on the system. Another input validation flaw allows an attacker to delete arbitrary files on the remote host. In addition, the existence of these two flaws indicates that IceWarp is vulnerable to cross-site scripting attack.

Solution

No solution is known at this time.