Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
icewarp web mail 5.5.1 vulnerabilities and exploits
(subscribe to this query)
760
VMScore
CVE-2005-4556
PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote malicious users to include arbitrary local and remote PHP files via a URL in the (1...
Merak Mail Server 8.3.0r
Deerfield Visnetic Mail Server 8.3.0 Build1
Icewarp Web Mail 5.5.1
2 EDB exploits
660
VMScore
CVE-2005-4558
IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users ...
Merak Mail Server 8.3.0r
Deerfield Visnetic Mail Server 8.3.0 Build1
Icewarp Web Mail 5.5.1
2 EDB exploits
505
VMScore
CVE-2005-4559
mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and layout_settings variables when an unrecognized HTTP_USER_AGENT string is provided, which allows rem...
Merak Mail Server 8.3.0r
Deerfield Visnetic Mail Server 8.3.0 Build1
Icewarp Web Mail 5.5.1
1 EDB exploit
505
VMScore
CVE-2005-4557
dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote malicious users to include arbitrary local files via a null byte (%00) in the lang parameter, possibly due to a directory traversal vulner...
Merak Mail Server 8.3.0r
Deerfield Visnetic Mail Server 8.3.0 Build1
Icewarp Web Mail 5.5.1
1 EDB exploit
505
VMScore
CVE-2005-3133
Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote malicious users to (1) delete arbitrary files or directories via a relative path to the id parameter to logout.html or (2) include ar...
Icewarp Web Mail 5.5.1
Merak Mail Server 8.2.4r
1 EDB exploit
450
VMScore
CVE-2005-3131
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote malicious users to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to...
Merak Mail Server 8.2.4r
Icewarp Web Mail 5.5.1
4 EDB exploits
445
VMScore
CVE-2005-3132
MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote malicious users to obtain sensitive information via a direct request to bwlist_inc.html, which reveals the path in an error message.
Icewarp Web Mail 5.5.1
Merak Mail Server 8.2.4r
383
VMScore
CVE-2006-2484
Cross-site scripting (XSS) vulnerability in index.html in IceWarp WebMail 5.5.1 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the PHPSESSID parameter.
Icewarp Web Mail 3.3.2
Icewarp Web Mail 3.4.1
Icewarp Web Mail 5.3
Icewarp Web Mail 5.3.1
Icewarp Web Mail 3.4.2
Icewarp Web Mail 3.5.0
Icewarp Web Mail 3.5.1
Icewarp Web Mail 5.3.2
Icewarp Web Mail 5.4
Icewarp Web Mail 3.1.4
Icewarp Web Mail 3.3.1
Icewarp Web Mail 5.2.7
Icewarp Web Mail 5.2.8
Icewarp Web Mail 1.40.00
Icewarp Web Mail 1.40.10
Icewarp Web Mail 4.1.4
Icewarp Web Mail 4.1.5
Icewarp Web Mail 5.5.1
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started