vendor:
IceWarp
by:
JameelNabbo
7.5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: IceWarp
Affected Version From: 10.4.2004
Affected Version To: 10.4.2004
Patch Exists: NO
Related CWE: CVE-2019-12593
CPE: a:icewarp:icewarp:10.4.4
Tags: packetstorm,cve,cve2019,lfi,icewarp
CVSS Metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Nuclei Metadata: {'max-request': 2, 'google-query': 'Powered By IceWarp 10.4.4', 'shodan-query': 'title:"icewarp"', 'vendor': 'icewarp', 'product': 'mail_server'}
Platforms Tested: Windows 10
2019
IceWarp <=10.4.4 local file include
The IceWarp version 10.4.4 is vulnerable to local file inclusion. An attacker can exploit this vulnerability by including local files and executing arbitrary code. This vulnerability has been assigned CVE-2019-12593.
Mitigation:
Upgrade to a patched version of IceWarp (version > 10.4.4).