Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) sql and (2) order_by elements in an XML search query.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Icewarp Merak邮件服务器Groupware组件多个SQL注入漏洞
Vulnerability Description
Merak Email Server是一个全面的办公室局域网或Internet通讯邮件解决方案。 Merak邮件服务器使用的基于Web的groupware组件允许用户存储联系人信息、标注、文件等。可使用搜索表单搜索所存储的项。当用户使用所提供的表单搜索某些文件时,会从浏览器向以下PHP脚本发送包含有XML搜索查询的HTTP POST请求: https://example.com/webmail/server/webmail.php: ----- HTTP POST request ------------
CVSS Information
N/A
Vulnerability Type
N/A