Vulnerabilities
Vulnerable Software
Icewarp:  >> Web Mail  >> 5.3.2  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in index.html in IceWarp WebMail 5.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the PHPSESSID parameter.
CVSS Score
4.3
EPSS Score
0.004
Published
2006-05-19
MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encryption in the (1) users.cfg, (2) settings.cfg, (3) users.dat or (4) user.dat files, which allows local users to extract the passwords.
CVSS Score
7.2
EPSS Score
0.0
Published
2005-05-02


Contact Us

Shodan ® - All rights reserved