IceWarp Web Mail Multiple Vulnerabilities

medium Nessus Network Monitor Plugin ID 3248

Synopsis

It is possible to retrieve or delete local files on the remote system through the WebMail.

Description

The remote host is running IceWarp Web Mail, a webmail solution available for the Microsoft Windows platform. The remote version of this software is vulnerable to a Directory Traversal vulnerability that may allow an attacker to retrieve arbitrary files on the system. Another input validation flaw allows an attacker to delete arbitrary files on the remote host. In addition, the existence of these two flaws indicates that IceWarp is vulnerable to cross-site scripting attack.

Solution

No solution is known at this time.

Plugin Details

Severity: Medium

ID: 3248

Family: CGI

Published: 10/3/2005

Updated: 3/6/2019

Nessus ID: 19782

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Temporal Vector: CVSS:3.0/E:H/RL:U/RC:X

Vulnerability Information

CPE: cpe:/a:icewarp:web_mail

Reference Information

CVE: CVE-2005-3131, CVE-2005-3133

BID: 14988, 14986, 14980