IceWarp Server是美国爱思华宝(IceWarp)公司的一款邮件服务器产品。该产品支持电子邮件归档、SmartAttach附件、自动迁移等。webmail component是其中的邮箱组件。 IceWarp Server 11.3.1.5版本中的webmail组件的‘language’参数存在安全漏洞。远程攻击者可利用该漏洞窃取用户会话,访问用户的webmail。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | IceWarp WebMail 11.3.1.5 is vulnerable to cross-site scripting via the language parameter. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-7855.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2017-14060 | ImageMagick 代码问题漏洞 | |
| CVE-2017-14062 | Libidn2 数字错误漏洞 | |
| CVE-2017-14063 | Async Http Client 安全漏洞 | |
| CVE-2017-14054 | FFmpeg 安全漏洞 | |
| CVE-2017-14055 | FFmpeg 安全漏洞 | |
| CVE-2017-14056 | FFmpeg 安全漏洞 | |
| CVE-2017-14057 | FFmpeg 安全漏洞 | |
| CVE-2017-14058 | FFmpeg 资源管理错误漏洞 | |
| CVE-2017-14059 | FFmpeg 安全漏洞 | |
| CVE-2017-14061 | Libidn2 数字错误漏洞 | |
| CVE-2016-0713 | Pivotal Software Cloud Foundry cf-release Gorouter 跨站脚本漏洞 | |
| CVE-2017-13708 | VX Search Enterprise 缓冲区错误漏洞 | |
| CVE-2017-13670 | BlackCat CMS 安全漏洞 | |
| CVE-2017-14048 | BlackCat CMS 安全漏洞 | |
| CVE-2017-14049 | BlackCat CMS 跨站脚本漏洞 | |
| CVE-2017-14050 | BlackCat CMS 安全漏洞 | |
| CVE-2017-14051 | Linux kernel 数字错误漏洞 | |
| CVE-2014-8675 | SOPlanning 安全漏洞 | |
| CVE-2017-14064 | Ruby 安全漏洞 | |
| CVE-2017-14070 | NexusPHP 跨站脚本漏洞 |
Showing top 20 of 34 CVEs. View all on vendor page → →
No comments yet