Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.902478
Kategorie:Web application abuses
Titel:IceWarp Mail Server < 10.3.3 XML Entity Injection and Information Disclosure Vulnerability
Zusammenfassung:The host is running IceWarp Mail Server and is prone to xml entity injection; and information disclosure vulnerability.
Beschreibung:Summary:
The host is running IceWarp Mail Server and is prone to xml entity injection
and information disclosure vulnerability.

Vulnerability Insight:
The flaws are due to:

- Certain input passed via SOAP messages to 'server/webmail.php' is not properly verified before being used. This
can be exploited to disclose the contents of arbitrary files.

- An unspecified script, which calls the 'phpinfo()' function, is stored with insecure permissions inside the web
root. This can be exploited to gain knowledge of sensitive information.

Vulnerability Impact:
Successful exploitation will allow attacker to gain access to potentially
sensitive information, and possibly cause denial-of-service conditions. Other attacks may also be possible.

Affected Software/OS:
IceWarp Mail Server 10.3.2 and prior.

Solution:
Upgrade to IceWarp Mail Server 10.3.3 or later.

CVSS Score:
6.4

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:P

Querverweis: BugTraq ID: 49753
Common Vulnerability Exposure (CVE) ID: CVE-2011-3579
http://www.securityfocus.com/bid/49753
Bugtraq: 20110923 TWSL2011-013: Multiple Vulnerabilities in IceWarp Mail Server (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2011-09/0145.html
https://www.trustwave.com/spiderlabs/advisories/TWSL2011-013.txt
http://www.osvdb.org/75721
http://securitytracker.com/id?1026093
http://securityreason.com/securityalert/8404
XForce ISS Database: icewarpwebmail-xml-info-disclosure(70025)
https://exchange.xforce.ibmcloud.com/vulnerabilities/70025
Common Vulnerability Exposure (CVE) ID: CVE-2011-3580
http://www.osvdb.org/75722
XForce ISS Database: icewarpwebmail-phpinfo-info-disc(70026)
https://exchange.xforce.ibmcloud.com/vulnerabilities/70026
CopyrightCopyright (C) 2011 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.