|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
IceWarp Web Mail contains a flaw that may allow a remote attacker to manipulate arbitrary files on the web server. The issue is due to the importaction.html script not properly sanitizing input passed to the "importfile" parameter. This may allow an attacker to supply any path within the web root and create or view an arbitrary file.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
OSVDB:
Web Related
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
IceWarp Web Mail
 |
5.3.0 |
5.3.2 |
Merak Mail Server
 |
7.6.0 |
7.6.4r |
|
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|