First published: Tue May 08 2018(Updated: )
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot) in the (2) script or (3) style parameter to webmail/old/calendar/minimizer/index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IceWarp Mail Server | <11.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1503 is a vulnerability in IceWarp Mail Server before version 11.2 that allows remote attackers to read arbitrary files through directory traversal.
The severity of CVE-2015-1503 is high with a severity score of 7.5.
We do not provide information on how to exploit vulnerabilities. Please refer to the provided references for more details.
Update IceWarp Mail Server to version 11.2.0 or higher to fix CVE-2015-1503.
You can find more information about CVE-2015-1503 in the provided references.