Korean
<< Back
VID 22342
Severity 40
Port 4096,32000
Protocol TCP
Class WWW
Detailed Description A version of IceWarp Web Mail which is older than version 5.3.1 is detected as running on the host. IceWarp Web Mail is a Web mail server for Microsoft Windows platforms. IceWarp versions prior to 5.3.1 are vulnerable to multiple vulnerabilities as follows:

1) HTML injection vulnerabilities in "send.html", "attachment.html", and "folderitem.html".
2) Simple encryption of users passwords.
3) File and directory creation vulnerability in "viewaction.html".

* Note: This check solely relied on the version number of the remote IceWarp Web Mail server to assess this vulnerability, so this might be a false positive.

* References:
http://archives.neohapsis.com/archives/bugtraq/2004-11/0068.html

* Platforms Affected:
IceWarp Software, IceWarp versions prior to 5.3.1
Microsoft Windows Any version
Recommendation Upgrade to the latest version of IceWarp Web Mail (5.3.1 or later), available from the IceWarp Download Web page at http://www.icewarp.com/
Related URL CVE-2004-1673,CVE-2004-1674 (CVE)
Related URL 11611 (SecurityFocus)
Related URL 17973,17974,17975,17976 (ISS)