|
|
IceWarp Universal WebMail PHPSESSID Parameter Cross-Site Scripting Vulnerability
|
Bugtraq ID:
|
17995
|
|
Class:
|
Input Validation Error
|
|
CVE:
|
|
|
Remote:
|
Yes
|
|
Local:
|
No
|
|
Published:
|
May 16 2006 12:00AM
|
|
Updated:
|
May 17 2006 07:24PM
|
|
Credit:
|
LiNuX_rOOt <LiNuX_rOOt1@hotmail.com> is credited with the discovery of this vulnerability.
|
|
Vulnerable:
|
IceWarp WebMail 5.5.1
IceWarp Web Mail 5.5.1
IceWarp Web Mail 5.4
IceWarp Web Mail 5.3.2
IceWarp Web Mail 5.3.1
IceWarp Web Mail 5.3
IceWarp Web Mail 5.2.8
IceWarp Web Mail 5.2.7
IceWarp Web Mail 4.1.5
IceWarp Web Mail 4.1.4
IceWarp Web Mail 3.5 .1
IceWarp Web Mail 3.5 .0
IceWarp Web Mail 3.4.2
IceWarp Web Mail 3.4.1
IceWarp Web Mail 3.3.2
IceWarp Web Mail 3.3.1
IceWarp Web Mail 3.1.4
IceWarp Web Mail 1.40.10
IceWarp Web Mail 1.40 .00
|
|
|
|
Not Vulnerable:
|
|
|

|