6.4
CVSSv2

CVE-2011-3579

Published: 30/09/2011 Updated: 29/08/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

server/webmail.php in IceWarp WebMail in IceWarp Mail Server prior to 10.3.3 allows remote malicious users to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference.

Vulnerable Product Search on Vulmon Subscribe to Product

icewarp mail server 10.0.3

icewarp mail server 10.0.4

icewarp mail server 10.2.1

icewarp mail server 10.2.2

icewarp mail server 9.4.2

icewarp mail server

icewarp mail server 10.3.1

icewarp mail server 10.1.4

icewarp mail server 10.2.0

icewarp mail server 9.4.0

icewarp mail server 9.4.1

icewarp mail server 10.0.7

icewarp mail server 10.0.8

icewarp mail server 10.1.1

icewarp mail server 10.3.0

icewarp mail server 9.3.0

icewarp mail server 10.1.2

icewarp mail server 10.1.3

icewarp mail server 9.3.1

icewarp mail server 9.3.2

Exploits

source: wwwsecurityfocuscom/bid/49753/info IceWarp Web Mail is prone to multiple information-disclosure vulnerabilities Attackers can exploit these issues to gain access to potentially sensitive information, and possibly cause denial-of-service conditions; other attacks may also be possible Proof-of-Concept: The following POST reque ...
IceWarp Mail Server versions 1032 and below suffer from XML external entity injection and PHP information disclosure vulnerabilities ...