vendor:
Universal WebMail
by:
Unknown
7.5
CVSS
HIGH
Input-Validation
79
CWE
Product Name: Universal WebMail
Affected Version From: Merak Mail Server 8.3.0.r, VisNetic MailServer 8.3.0 build 1
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:icewarp:universal_webmail
Platforms Tested:
2007
IceWarp Universal WebMail Input-Validation Vulnerabilities
The IceWarp Universal WebMail is prone to multiple input-validation vulnerabilities. An attacker can exploit these issues to include arbitrary local or remote files containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible. Additionally, an attacker can exploit these issues to obtain the contents of local files.
Mitigation:
Update to a patched version of Merak Mail Server or VisNetic MailServer.