Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
icewarp webmail server vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2022-35115
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) exists to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php.
Icewarp Webclient Dc2 13.0.2.9
6.1
CVSSv3
CVE-2020-27982
IceWarp 11.4.5.0 allows XSS via the language parameter.
Icewarp Mail Server 11.4.5
6.1
CVSSv3
CVE-2020-8512
In IceWarp Webmail Server up to and including 11.4.4.1, there is XSS in the /webmail/ color parameter.
Icewarp Icewarp Server
1 Github repository
6.1
CVSSv3
CVE-2019-19265
IceWarp WebMail Server 12.2.0 and 12.1.x prior to 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in notes for contacts.
Icewarp Mail Server
5.4
CVSSv3
CVE-2019-19266
IceWarp WebMail Server 12.2.0 and 12.1.x prior to 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for objects.
Icewarp Mail Server
7.5
CVSSv3
CVE-2019-12593
IceWarp Mail Server up to and including 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.
Icewarp Mail Server
1 EDB exploit
6.1
CVSSv3
CVE-2018-16324
In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field.
Icewarp Mail Server
7.5
CVSSv3
CVE-2015-1503
Multiple directory traversal vulnerabilities in IceWarp Mail Server prior to 11.2 allow remote malicious users to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot) in the (2) scrip...
Icewarp Mail Server
1 EDB exploit
6.1
CVSSv3
CVE-2017-7855
In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.
Icewarp Server 11.3.1.5
NA
CVE-2011-3579
server/webmail.php in IceWarp WebMail in IceWarp Mail Server prior to 10.3.3 allows remote malicious users to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaratio...
Icewarp Mail Server 10.0.3
Icewarp Mail Server 10.0.4
Icewarp Mail Server 10.2.1
Icewarp Mail Server 10.2.2
Icewarp Mail Server 9.4.2
Icewarp Mail Server
Icewarp Mail Server 10.3.1
Icewarp Mail Server 10.1.4
Icewarp Mail Server 10.2.0
Icewarp Mail Server 9.4.0
Icewarp Mail Server 9.4.1
Icewarp Mail Server 10.0.7
Icewarp Mail Server 10.0.8
Icewarp Mail Server 10.1.1
Icewarp Mail Server 10.3.0
Icewarp Mail Server 9.3.0
Icewarp Mail Server 10.1.2
Icewarp Mail Server 10.1.3
Icewarp Mail Server 9.3.1
Icewarp Mail Server 9.3.2
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »