7.8
CVSSv2

CVE-2015-1503

Published: 08/05/2018 Updated: 12/06/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in IceWarp Mail Server prior to 11.2 allow remote malicious users to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot) in the (2) script or (3) style parameter to webmail/old/calendar/minimizer/index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

icewarp mail server

Exploits

Vendor: IceWarp (wwwicewarpcom) Product: IceWarp Mail Server Version affected: 1111 and below Product description: IceWarp WebMail provides web-based access to email, calendars, contacts, files and shared data from any computer with a browser and Internet connection IceWarp Mail Server is a commercial mail and groupware server develop ...
IceWarp Mail Server versions prior to 1111 suffer from a directory traversal vulnerability ...