Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.902478
Categoría:Web application abuses
Título:IceWarp Mail Server < 10.3.3 Multiple Vulnerabilities
Resumen:IceWarp Mail Server is prone to multiple vulnerabilities.
Descripción:Summary:
IceWarp Mail Server is prone to multiple vulnerabilities.

Vulnerability Insight:
The flaws are due to:

- Certain input passed via SOAP messages to 'server/webmail.php' is not properly verified before
being used. This can be exploited to disclose the contents of arbitrary files.

- An unspecified script, which calls the 'phpinfo()' function, is stored with insecure permissions
inside the web root. This can be exploited to gain knowledge of sensitive information.

Vulnerability Impact:
Successful exploitation will allow attacker to gain access to
potentially sensitive information, and possibly cause denial of service conditions. Other attacks
may also be possible.

Affected Software/OS:
IceWarp Mail Server 10.3.2 and prior.

Solution:
Update to version 10.3.3 or later.

CVSS Score:
6.4

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-3579
BugTraq ID: 49753
http://www.securityfocus.com/bid/49753
Bugtraq: 20110923 TWSL2011-013: Multiple Vulnerabilities in IceWarp Mail Server (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2011-09/0145.html
https://www.trustwave.com/spiderlabs/advisories/TWSL2011-013.txt
http://www.osvdb.org/75721
http://securitytracker.com/id?1026093
http://securityreason.com/securityalert/8404
XForce ISS Database: icewarpwebmail-xml-info-disclosure(70025)
https://exchange.xforce.ibmcloud.com/vulnerabilities/70025
Common Vulnerability Exposure (CVE) ID: CVE-2011-3580
http://www.osvdb.org/75722
XForce ISS Database: icewarpwebmail-phpinfo-info-disc(70026)
https://exchange.xforce.ibmcloud.com/vulnerabilities/70026
CopyrightCopyright (C) 2011 Greenbone Networks GmbH

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.