Filtered by vendor Icewarp
Subscriptions
Total
65 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-0246 | 1 Icewarp | 1 Icewarp | 2024-11-14 | 4.3 Medium |
A vulnerability classified as problematic has been found in IceWarp 12.0.2.1/12.0.3.1. This affects an unknown part of the file /install/ of the component Utility Download Handler. The manipulation of the argument lang with the input 1%27"()%26%25<zzz><ScRiPt>alert(document.domain)</ScRiPt> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249759. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
CVE-2023-37728 | 1 Icewarp | 1 Icewarp | 2024-10-24 | 6.1 Medium |
IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter. | ||||
CVE-2021-36580 | 1 Icewarp | 2 Icewarp Server, Mail Server | 2024-10-23 | 6.1 Medium |
Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter. | ||||
CVE-2023-39699 | 1 Icewarp | 1 Mail Server | 2024-10-03 | 9.8 Critical |
IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. This vulnerability allows attackers to include or execute files from the local file system of the targeted server. | ||||
CVE-2023-39700 | 1 Icewarp | 1 Mail Server | 2024-10-03 | 6.1 Medium |
IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter. | ||||
CVE-2023-39600 | 1 Icewarp | 1 Icewarp | 2024-10-02 | 6.1 Medium |
IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter. | ||||
CVE-2023-39598 | 1 Icewarp | 1 Webclient | 2024-09-30 | 6.1 Medium |
Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter. | ||||
CVE-2023-41013 | 1 Icewarp | 1 Icewarp | 2024-09-26 | 6.1 Medium |
Cross Site Scripting (XSS) in Webmail Calendar in IceWarp 10.3.1 allows remote attackers to inject arbitrary web script or HTML via the "p4" field. | ||||
CVE-2023-40779 | 1 Icewarp | 1 Deep Castle G2 | 2024-09-25 | 6.1 Medium |
An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL. | ||||
CVE-2023-43319 | 1 Icewarp | 1 Webclient | 2024-09-24 | 6.1 Medium |
Cross Site Scripting (XSS) vulnerability in the Sign-In page of IceWarp WebClient 10.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter. | ||||
CVE-2002-1899 | 1 Icewarp | 1 Web Mail | 2024-09-17 | N/A |
Cross-site scripting (XSS) vulnerability in IceWarp Web Mail 3.3.3 and 3.4.5 allows remote attackers to inject arbitrary web script or HTML via the "Full Name" (addressname) parameter. | ||||
CVE-2002-0258 | 2 Icewarp, Merak | 2 Web Mail, Mail Server | 2024-08-08 | N/A |
Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain privileges as that user, e.g. by extracting the ID from the user's answer or forward URLs. | ||||
CVE-2004-1674 | 2 Icewarp, Merak | 2 Web Mail, Mail Server | 2024-08-08 | N/A |
viewaction.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to (1) delete arbitrary files via the originalfolder parameter or (2) move arbitrary files via the messageid parameter. | ||||
CVE-2004-1670 | 2 Icewarp, Merak | 2 Web Mail, Mail Server | 2024-08-08 | N/A |
Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary directories via a .. (dot dot) in the user parameter to viewaction.html or (2) rename arbitrary files via a ....// (doubled dot dot) in the folderold or folder parameters to folders.html. | ||||
CVE-2004-1669 | 2 Icewarp, Merak | 2 Web Mail, Mail Server | 2024-08-08 | N/A |
Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html. | ||||
CVE-2004-1672 | 1 Icewarp | 1 Web Mail | 2024-08-08 | N/A |
attachment.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to view other users' attachments by specifying the username and message ID in an HTTP request. | ||||
CVE-2004-1671 | 1 Icewarp | 1 Web Mail | 2024-08-08 | N/A |
Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to gain sensitive information via a direct request to (1) accountsettings_add.html or (2) topmenu.html. | ||||
CVE-2004-1673 | 1 Icewarp | 1 Web Mail | 2024-08-08 | N/A |
accountsettings_add.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allow remote attackers to create text files with arbitrary content via the accountid parameter. | ||||
CVE-2005-4559 | 3 Deerfield, Icewarp, Merak | 3 Visnetic Mail Server, Web Mail, Mail Server | 2024-08-07 | N/A |
mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and layout_settings variables when an unrecognized HTTP_USER_AGENT string is provided, which allows remote attackers to access arbitrary files via a request with an unrecognized User Agent that also specifies the desired default_layout and layout_settings parameters. | ||||
CVE-2005-4556 | 3 Deerfield, Icewarp, Merak | 3 Visnetic Mail Server, Web Mail, Mail Server | 2024-08-07 | N/A |
PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote attackers to include arbitrary local and remote PHP files via a URL in the (1) lang_settings and (2) language parameters in (a) accounts/inc/include.php and (b) admin/inc/include.php. |