4.3
CVSSv2

CVE-2009-1469

Published: 05/05/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server prior to 9.4.2 makes it easier for remote malicious users to trick a user into disclosing credentials via CRLF sequences preceding a Reply-To header in the subject element of an XML document, as demonstrated by triggering an e-mail message from the server that contains a user's correct credentials, and requests that the user compose a reply that includes this message.

Vulnerable Product Search on Vulmon Subscribe to Product

icewarp webmail server 2.10.170

icewarp webmail server 2.10.200

icewarp webmail server 2.10.290

icewarp webmail server 2.10.320

icewarp webmail server 3.00.120

icewarp webmail server 3.00.130

icewarp webmail server 4.2.1

icewarp webmail server 4.2.2

icewarp webmail server 5.4.1

icewarp webmail server 5.4.2

icewarp webmail server 5.5.7

icewarp webmail server 5.7.3

icewarp webmail server 6.0.2

icewarp webmail server 6.0.3

icewarp webmail server 6.0.5

icewarp webmail server 7.1.6

icewarp webmail server 7.2.0

icewarp webmail server 8.0.1

icewarp webmail server 8.0.3

icewarp webmail server 8.9.1

icewarp webmail server 9.0.0

icewarp webmail server 9.1.0

icewarp email server 2.10.105

icewarp email server 2.10.110

icewarp email server 2.10.200

icewarp email server 2.10.210

icewarp email server 2.10.320

icewarp email server 2.10.330

icewarp email server 3.00.120

icewarp email server 3.00.130

icewarp email server 4.2.1

icewarp email server 4.2.2

icewarp email server 5.3.2

icewarp email server 5.4.1

icewarp email server 5.5.6

icewarp email server 5.5.7

icewarp email server 5.9.4

icewarp email server 6.0.2

icewarp email server 7.1.6

icewarp email server 7.2.0

icewarp webmail server 2.10.165

icewarp webmail server 2.10.105

icewarp webmail server 2.10.310

icewarp webmail server 2.10.280

icewarp webmail server 3.00.100

icewarp webmail server 3.00.110

icewarp webmail server 4.10.040

icewarp webmail server 4.10.050

icewarp webmail server 5.1.5

icewarp webmail server 5.3.2

icewarp webmail server 5.5.5

icewarp webmail server 5.5.6

icewarp webmail server 5.8.6

icewarp webmail server 5.9.4

icewarp webmail server 7.0.1

icewarp webmail server 7.1.4

icewarp webmail server 7.6.0

icewarp webmail server 7.6.4

icewarp webmail server 8.3.8

icewarp webmail server 8.5.0

icewarp webmail server 2.10.190

icewarp webmail server 5.3.0

icewarp email server 2.10.170

icewarp email server 2.10.190

icewarp email server 2.10.280

icewarp email server 2.10.290

icewarp email server 2.10.310

icewarp email server 3.00.100

icewarp email server 3.00.110

icewarp email server 4.10.040

icewarp email server 4.10.050

icewarp email server 5.1.5

icewarp email server 5.3.0

icewarp email server 5.5.4

icewarp email server 5.5.5

icewarp email server 5.8.5

icewarp webmail server 2.10.210

icewarp webmail server 2.10.220

icewarp webmail server 2.10.330

icewarp webmail server 2.10.331

icewarp webmail server 3.00.140

icewarp webmail server 3.10.011

icewarp webmail server 4.2.3

icewarp webmail server 4.4.1

icewarp webmail server 4.4.2

icewarp webmail server 5.4.3

icewarp webmail server 5.4.4

icewarp webmail server 5.8.2

icewarp webmail server 5.8.3

icewarp webmail server 6.0.7

icewarp webmail server 6.1.0

icewarp webmail server 7.4.0

icewarp webmail server 7.4.2

icewarp webmail server 8.0.2

icewarp webmail server 8.2.0

icewarp webmail server

icewarp webmail server 2.10.110

icewarp email server 2.10.115

icewarp email server 2.10.140

icewarp email server 2.10.220

icewarp email server 2.10.240

icewarp email server 2.10.331

icewarp email server 2.10.340

icewarp email server 3.00.140

icewarp email server 3.10.011

icewarp email server 4.2.3

icewarp email server 4.4.1

icewarp email server 5.4.2

icewarp email server 5.4.3

icewarp email server 5.7.3

icewarp email server 5.8.2

icewarp email server 6.0.3

icewarp email server 6.0.5

icewarp email server 6.0.7

icewarp email server 7.4.0

icewarp email server 7.4.2

icewarp email server 8.0.3

icewarp email server 8.2.0

icewarp email server 9.1.0

icewarp email server 9.2.0

icewarp email server

icewarp email server 5.8.6

icewarp email server 7.0.1

icewarp email server 7.1.4

icewarp email server 7.6.0

icewarp email server 7.6.4

icewarp email server 8.3.8

icewarp email server 8.5.0

icewarp email server 8.0.1

icewarp email server 8.0.2

icewarp email server 8.9.1

icewarp email server 9.0.0

icewarp webmail server 2.10.115

icewarp webmail server 2.10.150

icewarp webmail server 2.10.240

icewarp webmail server 2.10.250

icewarp webmail server 2.10.260

icewarp webmail server 2.10.340

icewarp webmail server 2.10.350

icewarp webmail server 3.10.110

icewarp webmail server 4.00.30

icewarp webmail server 5.1.2

icewarp webmail server 5.1.3

icewarp webmail server 5.5.3

icewarp webmail server 5.5.4

icewarp webmail server 5.8.4

icewarp webmail server 5.8.5

icewarp webmail server 6.2.1

icewarp webmail server 2.10.360

icewarp webmail server 7.4.5

icewarp webmail server 7.5.2

icewarp webmail server 8.2.2

icewarp webmail server 8.3.5

icewarp webmail server 9.2.0

icewarp webmail server 2.10.140

icewarp email server 2.10.150

icewarp email server 2.10.165

icewarp email server 2.10.250

icewarp email server 2.10.260

icewarp email server 2.10.350

icewarp email server 2.10.360

icewarp email server 3.10.110

icewarp email server 4.00.30

icewarp email server 4.4.2

icewarp email server 5.1.2

icewarp email server 5.1.3

icewarp email server 5.4.4

icewarp email server 5.5.3

icewarp email server 5.8.3

icewarp email server 5.8.4

icewarp email server 6.1.0

icewarp email server 6.2.1

icewarp email server 7.4.5

icewarp email server 7.5.2

icewarp email server 8.2.2

icewarp email server 8.3.5

Exploits

source: wwwsecurityfocuscom/bid/34827/info IceWarp Merak Mail Server is prone to an input-validation vulnerability because it uses client-supplied data when performing a 'Forgot Password' function Attackers can exploit this issue via social-engineering techniques to obtain valid users' login credentials; other attacks may also be possib ...
RedTeam Pentesting discovered that the emails sent by the IceWarp WebMail Server when using the "Forgot Password" function are generated on the client side Version 941 is affected ...