| VID |
22342 |
| Severity |
40 |
| Port |
4096,32000 |
| Protocol |
TCP |
| Class |
WWW |
| Detailed Description |
A version of IceWarp Web Mail which is older than version 5.3.1 is detected as running on the host. IceWarp Web Mail is a Web mail server for Microsoft Windows platforms. IceWarp versions prior to 5.3.1 are vulnerable to multiple vulnerabilities as follows:
1) HTML injection vulnerabilities in "send.html", "attachment.html", and "folderitem.html". 2) Simple encryption of users passwords. 3) File and directory creation vulnerability in "viewaction.html".
* Note: This check solely relied on the version number of the remote IceWarp Web Mail server to assess this vulnerability, so this might be a false positive.
* References: http://archives.neohapsis.com/archives/bugtraq/2004-11/0068.html
* Platforms Affected: IceWarp Software, IceWarp versions prior to 5.3.1 Microsoft Windows Any version |
| Recommendation |
Upgrade to the latest version of IceWarp Web Mail (5.3.1 or later), available from the IceWarp Download Web page at http://www.icewarp.com/ |
| Related URL |
CVE-2004-1673,CVE-2004-1674 (CVE) |
| Related URL |
11611 (SecurityFocus) |
| Related URL |
17973,17974,17975,17976 (ISS) |
|