vendor:
IceWarp Mail Server
by:
Piotr Karolak of Trustwave's SpiderLabs
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: IceWarp Mail Server
Affected Version From: 11.1.1
Affected Version To: Below 11.1.1
Patch Exists: YES
Related CWE: CVE-2015-1503
CPE: a:icewarp:icewarp_mail_server
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows and Linux
2015
Multiple Unauthenticated Directory Traversal
The unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request to the /webmail/client/skins/default/css/css.php. Directory Traversal is a vulnerability which allows attackers to access restricted directories and execute commands outside of the web server's root directory.
Mitigation:
Ensure that the web server is configured to restrict access to sensitive files and directories.