Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
icewarp icewarp server vulnerabilities and exploits
(subscribe to this query)
445
VMScore
CVE-2005-1489
Unknown vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to obtain the full path of the server via certain requests to (1) calendar_addevent.html, (2) calendar_event.html, or (3) calendar_task.html.
Merak Mail Server 8.0.3
Icewarp Web Mail 5.4.2
NA
CVE-2022-35115
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) exists to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php.
Icewarp Webclient Dc2 13.0.2.9
510
VMScore
CVE-2005-0320
Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote malicious users to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) n...
Icewarp Web Mail 5.3
2 EDB exploits
445
VMScore
CVE-2006-0817
Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer prior to 8.5.0.5 allows remote malicious users to include arbitrary files via a full Windows path and drive letter in the (1)...
Merak Mail Server 8.3.8r
Deerfield Visnetic Mail Server 8.3.5
Icewarp Web Mail 5.6.0
356
VMScore
CVE-2006-0818
Absolute path directory traversal vulnerability in (1) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (2) VisNetic MailServer prior to 8.5.0.5 allows remote authenticated users to include arbitrary files via a modified language parameter and a full Wi...
Merak Mail Server 8.3.8r
Deerfield Visnetic Mail Server 8.3.5
Icewarp Web Mail 5.6.0
NA
CVE-2023-40779
An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote malicious user to execute arbitrary code via a crafted request to the URL.
Icewarp Deep Castle G2 13.0.1.2
760
VMScore
CVE-2005-4556
PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote malicious users to include arbitrary local and remote PHP files via a URL in the (1...
Deerfield Visnetic Mail Server 8.3.0 Build1
Merak Mail Server 8.3.0r
Icewarp Web Mail 5.5.1
2 EDB exploits
660
VMScore
CVE-2005-4558
IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users ...
Deerfield Visnetic Mail Server 8.3.0 Build1
Merak Mail Server 8.3.0r
Icewarp Web Mail 5.5.1
2 EDB exploits
505
VMScore
CVE-2005-4559
mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and layout_settings variables when an unrecognized HTTP_USER_AGENT string is provided, which allows rem...
Deerfield Visnetic Mail Server 8.3.0 Build1
Merak Mail Server 8.3.0r
Icewarp Web Mail 5.5.1
1 EDB exploit
505
VMScore
CVE-2005-4557
dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote malicious users to include arbitrary local files via a null byte (%00) in the lang parameter, possibly due to a directory traversal vulner...
Deerfield Visnetic Mail Server 8.3.0 Build1
Merak Mail Server 8.3.0r
Icewarp Web Mail 5.5.1
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
privilege
CVE-2022-48762
CVE-2022-48751
CVE-2024-37079
CVE-2024-30848
LFI
man-in-the-middle
CVE-2022-48736
CVE-2024-30103
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5