First published: Tue May 05 2009(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the body of a message, related to the email view and incorrect HTML filtering in the cleanHTML function in server/inc/tools.php; or the (2) title, (3) link, or (4) description element in an RSS feed, related to the getHTML function in server/inc/rss/item.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Merak Mail Server | <=9.3.0 | |
Merak Mail Server | =2.10.105 | |
Merak Mail Server | =2.10.110 | |
Merak Mail Server | =2.10.115 | |
Merak Mail Server | =2.10.140 | |
Merak Mail Server | =2.10.150 | |
Merak Mail Server | =2.10.165 | |
Merak Mail Server | =2.10.170 | |
Merak Mail Server | =2.10.190 | |
Merak Mail Server | =2.10.200 | |
Merak Mail Server | =2.10.210 | |
Merak Mail Server | =2.10.220 | |
Merak Mail Server | =2.10.240 | |
Merak Mail Server | =2.10.250 | |
Merak Mail Server | =2.10.260 | |
Merak Mail Server | =2.10.280 | |
Merak Mail Server | =2.10.290 | |
Merak Mail Server | =2.10.310 | |
Merak Mail Server | =2.10.320 | |
Merak Mail Server | =2.10.330 | |
Merak Mail Server | =2.10.331 | |
Merak Mail Server | =2.10.340 | |
Merak Mail Server | =2.10.350 | |
Merak Mail Server | =2.10.360 | |
Merak Mail Server | =3.00.100 | |
Merak Mail Server | =3.00.110 | |
Merak Mail Server | =3.00.120 | |
Merak Mail Server | =3.00.130 | |
Merak Mail Server | =3.00.140 | |
Merak Mail Server | =3.10.011 | |
Merak Mail Server | =3.10.110 | |
Merak Mail Server | =4.00.30 | |
Merak Mail Server | =4.2.1 | |
Merak Mail Server | =4.2.2 | |
Merak Mail Server | =4.2.3 | |
Merak Mail Server | =4.4.1 | |
Merak Mail Server | =4.4.2 | |
Merak Mail Server | =4.10.040 | |
Merak Mail Server | =4.10.050 | |
Merak Mail Server | =5.1.2 | |
Merak Mail Server | =5.1.3 | |
Merak Mail Server | =5.1.5 | |
Merak Mail Server | =5.3.0 | |
Merak Mail Server | =5.3.2 | |
Merak Mail Server | =5.4.1 | |
Merak Mail Server | =5.4.2 | |
Merak Mail Server | =5.4.3 | |
Merak Mail Server | =5.4.4 | |
Merak Mail Server | =5.5.3 | |
Merak Mail Server | =5.5.4 | |
Merak Mail Server | =5.5.5 | |
Merak Mail Server | =5.5.6 | |
Merak Mail Server | =5.5.7 | |
Merak Mail Server | =5.7.3 | |
Merak Mail Server | =5.8.2 | |
Merak Mail Server | =5.8.3 | |
Merak Mail Server | =5.8.4 | |
Merak Mail Server | =5.8.5 | |
Merak Mail Server | =5.8.6 | |
Merak Mail Server | =5.9.4 | |
Merak Mail Server | =6.0.2 | |
Merak Mail Server | =6.0.3 | |
Merak Mail Server | =6.0.5 | |
Merak Mail Server | =6.0.7 | |
Merak Mail Server | =6.1.0 | |
Merak Mail Server | =6.2.1 | |
Merak Mail Server | =7.0.1 | |
Merak Mail Server | =7.1.4 | |
Merak Mail Server | =7.1.6 | |
Merak Mail Server | =7.2.0 | |
Merak Mail Server | =7.4.0 | |
Merak Mail Server | =7.4.2 | |
Merak Mail Server | =7.4.5 | |
Merak Mail Server | =7.5.2 | |
Merak Mail Server | =7.6.0 | |
Merak Mail Server | =7.6.4 | |
Merak Mail Server | =8.0.1 | |
Merak Mail Server | =8.0.2 | |
Merak Mail Server | =8.0.3 | |
Merak Mail Server | =8.2.0 | |
Merak Mail Server | =8.2.2 | |
Merak Mail Server | =8.3.5 | |
Merak Mail Server | =8.3.8 | |
Merak Mail Server | =8.5.0 | |
Merak Mail Server | =8.9.1 | |
Merak Mail Server | =9.0.0 | |
Merak Mail Server | =9.1.0 | |
Merak Mail Server | =9.2.0 | |
IceWarp | <=9.3.0 | |
IceWarp | =2.10.105 | |
IceWarp | =2.10.110 | |
IceWarp | =2.10.115 | |
IceWarp | =2.10.140 | |
IceWarp | =2.10.150 | |
IceWarp | =2.10.165 | |
IceWarp | =2.10.170 | |
IceWarp | =2.10.190 | |
IceWarp | =2.10.200 | |
IceWarp | =2.10.210 | |
IceWarp | =2.10.220 | |
IceWarp | =2.10.240 | |
IceWarp | =2.10.250 | |
IceWarp | =2.10.260 | |
IceWarp | =2.10.280 | |
IceWarp | =2.10.290 | |
IceWarp | =2.10.310 | |
IceWarp | =2.10.320 | |
IceWarp | =2.10.330 | |
IceWarp | =2.10.331 | |
IceWarp | =2.10.340 | |
IceWarp | =2.10.350 | |
IceWarp | =2.10.360 | |
IceWarp | =3.00.100 | |
IceWarp | =3.00.110 | |
IceWarp | =3.00.120 | |
IceWarp | =3.00.130 | |
IceWarp | =3.00.140 | |
IceWarp | =3.10.011 | |
IceWarp | =3.10.110 | |
IceWarp | =4.00.30 | |
IceWarp | =4.2.1 | |
IceWarp | =4.2.2 | |
IceWarp | =4.2.3 | |
IceWarp | =4.4.1 | |
IceWarp | =4.4.2 | |
IceWarp | =4.10.040 | |
IceWarp | =4.10.050 | |
IceWarp | =5.1.2 | |
IceWarp | =5.1.3 | |
IceWarp | =5.1.5 | |
IceWarp | =5.3.0 | |
IceWarp | =5.3.2 | |
IceWarp | =5.4.1 | |
IceWarp | =5.4.2 | |
IceWarp | =5.4.3 | |
IceWarp | =5.4.4 | |
IceWarp | =5.5.3 | |
IceWarp | =5.5.4 | |
IceWarp | =5.5.5 | |
IceWarp | =5.5.6 | |
IceWarp | =5.5.7 | |
IceWarp | =5.7.3 | |
IceWarp | =5.8.2 | |
IceWarp | =5.8.3 | |
IceWarp | =5.8.4 | |
IceWarp | =5.8.5 | |
IceWarp | =5.8.6 | |
IceWarp | =5.9.4 | |
IceWarp | =6.0.2 | |
IceWarp | =6.0.3 | |
IceWarp | =6.0.5 | |
IceWarp | =6.0.7 | |
IceWarp | =6.1.0 | |
IceWarp | =6.2.1 | |
IceWarp | =7.0.1 | |
IceWarp | =7.1.4 | |
IceWarp | =7.1.6 | |
IceWarp | =7.2.0 | |
IceWarp | =7.4.0 | |
IceWarp | =7.4.2 | |
IceWarp | =7.4.5 | |
IceWarp | =7.5.2 | |
IceWarp | =7.6.0 | |
IceWarp | =7.6.4 | |
IceWarp | =8.0.1 | |
IceWarp | =8.0.2 | |
IceWarp | =8.0.3 | |
IceWarp | =8.2.0 | |
IceWarp | =8.2.2 | |
IceWarp | =8.3.5 | |
IceWarp | =8.3.8 | |
IceWarp | =8.5.0 | |
IceWarp | =8.9.1 | |
IceWarp | =9.0.0 | |
IceWarp | =9.1.0 | |
IceWarp | =9.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1467 is classified as a medium severity vulnerability, allowing remote attackers to exploit the system.
To fix CVE-2009-1467, upgrade to IceWarp eMail Server version 9.4.2 or later and ensure proper HTML filtering.
CVE-2009-1467 affects multiple versions of IceWarp eMail Server and WebMail Server before version 9.4.2.
Attackers can inject arbitrary web scripts or HTML into emails, leading to cross-site scripting (XSS) attacks.
Check if your IceWarp eMail Server or WebMail Server version is below 9.4.2 to determine vulnerability to CVE-2009-1467.