This site is deprecated. Please
CLICK HERE for latest updates
Short Name |
HTTP:DIR:ICEWARP-MAILSRVR-LFI
|
Severity |
Major
|
Recommended |
No
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
IceWarp Mail Server Directory Traversal
|
Release Date |
2020/01/30
|
Update Number |
3250
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+
|
HTTP: IceWarp Mail Server Directory Traversal
This signature detects attempts to exploit a known vulnerability against IceWarp Mail Server. A successful attack can lead to directory traversal and arbitrary code execution.
Extended Description
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot) in the (2) script or (3) style parameter to webmail/old/calendar/minimizer/index.php.
Affected Products
- Icewarp mail_server 10.0.3
- Icewarp mail_server 10.0.4
- Icewarp mail_server 10.0.5
- Icewarp mail_server 10.0.6
- Icewarp mail_server 10.0.7
- Icewarp mail_server 10.0.8
- Icewarp mail_server 10.1.0
- Icewarp mail_server 10.1.1
- Icewarp mail_server 10.1.2
- Icewarp mail_server 10.1.3
- Icewarp mail_server 10.1.4
- Icewarp mail_server 10.2.0
- Icewarp mail_server 10.2.1
- Icewarp mail_server 10.2.2
- Icewarp mail_server 10.3.0
- Icewarp mail_server 10.3.1
- Icewarp mail_server 10.3.2
- Icewarp mail_server 10.3.3
- Icewarp mail_server 10.3.4
- Icewarp mail_server 10.3.5
- Icewarp mail_server 10.4.0
- Icewarp mail_server 10.4.1
- Icewarp mail_server 10.4.2
- Icewarp mail_server 10.4.3
- Icewarp mail_server 10.4.4
- Icewarp mail_server 10.4.5
- Icewarp mail_server 11.0.0
- Icewarp mail_server 11.0.1
- Icewarp mail_server 11.1.0
- Icewarp mail_server 11.1.1
- Icewarp mail_server 11.1.2
- Icewarp mail_server 9.3.1
- Icewarp mail_server 9.3.2
- Icewarp mail_server 9.4.0
- Icewarp mail_server 9.4.1
- Icewarp mail_server 9.4.2
References