IceWarp Universal WebMail PHPSESSID Parameter Cross-Site Scripting Vulnerability

Bugtraq ID: 17995
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: May 16 2006 12:00AM
Updated: May 17 2006 07:24PM
Credit: LiNuX_rOOt <LiNuX_rOOt1@hotmail.com> is credited with the discovery of this vulnerability.
Vulnerable: IceWarp WebMail 5.5.1
IceWarp Web Mail 5.5.1
IceWarp Web Mail 5.4
IceWarp Web Mail 5.3.2
IceWarp Web Mail 5.3.1
IceWarp Web Mail 5.3
IceWarp Web Mail 5.2.8
IceWarp Web Mail 5.2.7
IceWarp Web Mail 4.1.5
IceWarp Web Mail 4.1.4
IceWarp Web Mail 3.5 .1
IceWarp Web Mail 3.5 .0
IceWarp Web Mail 3.4.2
IceWarp Web Mail 3.4.1
IceWarp Web Mail 3.3.2
IceWarp Web Mail 3.3.1
IceWarp Web Mail 3.1.4
IceWarp Web Mail 1.40.10
IceWarp Web Mail 1.40 .00
Not Vulnerable:


 

Privacy Statement
Copyright 2010, SecurityFocus