server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference.
2011-09-30T17:55:01.180
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.4 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:P
10.0
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | icewarp | mail_server | ≤ 10.3.2 | Yes |
| Application | icewarp | mail_server | 9.3.0 | Yes |
| Application | icewarp | mail_server | 9.3.1 | Yes |
| Application | icewarp | mail_server | 9.3.2 | Yes |
| Application | icewarp | mail_server | 9.4.0 | Yes |
| Application | icewarp | mail_server | 9.4.1 | Yes |
| Application | icewarp | mail_server | 9.4.2 | Yes |
| Application | icewarp | mail_server | 10.0.3 | Yes |
| Application | icewarp | mail_server | 10.0.4 | Yes |
| Application | icewarp | mail_server | 10.0.7 | Yes |
| Application | icewarp | mail_server | 10.0.8 | Yes |
| Application | icewarp | mail_server | 10.1.1 | Yes |
| Application | icewarp | mail_server | 10.1.2 | Yes |
| Application | icewarp | mail_server | 10.1.3 | Yes |
| Application | icewarp | mail_server | 10.1.4 | Yes |
| Application | icewarp | mail_server | 10.2.0 | Yes |
| Application | icewarp | mail_server | 10.2.1 | Yes |
| Application | icewarp | mail_server | 10.2.2 | Yes |
| Application | icewarp | mail_server | 10.3.0 | Yes |
| Application | icewarp | mail_server | 10.3.1 | Yes |