Vulnerabilities (CVE)

Filtered by vendor Icewarp Subscribe
Filtered by product Mail Server
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-3579 1 Icewarp 1 Mail Server 2017-08-29 6.4 MEDIUM N/A
server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference.
CVE-2011-3580 1 Icewarp 1 Mail Server 2017-08-29 5.0 MEDIUM N/A
IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to obtain configuration information via a direct request to the /server URI, which triggers a call to the phpinfo function.