CVE-2015-1503: Path Traversal
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot) in the (2) script or (3) style parameter to webmail/old/calendar/minimizer/index.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-1503?
CVE-2015-1503 is a vulnerability in IceWarp Mail Server before version 11.2 that allows remote attackers to read arbitrary files through directory traversal.
What is the severity of CVE-2015-1503?
The severity of CVE-2015-1503 is high with a severity score of 7.5.
How do I exploit CVE-2015-1503?
We do not provide information on how to exploit vulnerabilities. Please refer to the provided references for more details.
How do I fix CVE-2015-1503?
Update IceWarp Mail Server to version 11.2.0 or higher to fix CVE-2015-1503.
Where can I find more information about CVE-2015-1503?
You can find more information about CVE-2015-1503 in the provided references.