CVE-2009-1467
05.05.2009, 20:30
Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the body of a message, related to the email view and incorrect HTML filtering in the cleanHTML function in server/inc/tools.php; or the (2) title, (3) link, or (4) description element in an RSS feed, related to the getHTML function in server/inc/rss/item.php.
Vendor | Product | Version |
---|---|---|
icewarp | email_server | 𝑥 ≤ 9.3.0 |
icewarp | email_server | 2.10.105 |
icewarp | email_server | 2.10.110 |
icewarp | email_server | 2.10.115 |
icewarp | email_server | 2.10.140 |
icewarp | email_server | 2.10.150 |
icewarp | email_server | 2.10.165 |
icewarp | email_server | 2.10.170 |
icewarp | email_server | 2.10.190 |
icewarp | email_server | 2.10.200 |
icewarp | email_server | 2.10.210 |
icewarp | email_server | 2.10.220 |
icewarp | email_server | 2.10.240 |
icewarp | email_server | 2.10.250 |
icewarp | email_server | 2.10.260 |
icewarp | email_server | 2.10.280 |
icewarp | email_server | 2.10.290 |
icewarp | email_server | 2.10.310 |
icewarp | email_server | 2.10.320 |
icewarp | email_server | 2.10.330 |
icewarp | email_server | 2.10.331 |
icewarp | email_server | 2.10.340 |
icewarp | email_server | 2.10.350 |
icewarp | email_server | 2.10.360 |
icewarp | email_server | 3.00.100 |
icewarp | email_server | 3.00.110 |
icewarp | email_server | 3.00.120 |
icewarp | email_server | 3.00.130 |
icewarp | email_server | 3.00.140 |
icewarp | email_server | 3.10.011 |
icewarp | email_server | 3.10.110 |
icewarp | email_server | 4.00.30 |
icewarp | email_server | 4.2.1 |
icewarp | email_server | 4.2.2 |
icewarp | email_server | 4.2.3 |
icewarp | email_server | 4.4.1 |
icewarp | email_server | 4.4.2 |
icewarp | email_server | 4.10.040 |
icewarp | email_server | 4.10.050 |
icewarp | email_server | 5.1.2 |
icewarp | email_server | 5.1.3 |
icewarp | email_server | 5.1.5 |
icewarp | email_server | 5.3.0 |
icewarp | email_server | 5.3.2 |
icewarp | email_server | 5.4.1 |
icewarp | email_server | 5.4.2 |
icewarp | email_server | 5.4.3 |
icewarp | email_server | 5.4.4 |
icewarp | email_server | 5.5.3 |
icewarp | email_server | 5.5.4 |
icewarp | email_server | 5.5.5 |
icewarp | email_server | 5.5.6 |
icewarp | email_server | 5.5.7 |
icewarp | email_server | 5.7.3 |
icewarp | email_server | 5.8.2 |
icewarp | email_server | 5.8.3 |
icewarp | email_server | 5.8.4 |
icewarp | email_server | 5.8.5 |
icewarp | email_server | 5.8.6 |
icewarp | email_server | 5.9.4 |
icewarp | email_server | 6.0.2 |
icewarp | email_server | 6.0.3 |
icewarp | email_server | 6.0.5 |
icewarp | email_server | 6.0.7 |
icewarp | email_server | 6.1.0 |
icewarp | email_server | 6.2.1 |
icewarp | email_server | 7.0.1 |
icewarp | email_server | 7.1.4 |
icewarp | email_server | 7.1.6 |
icewarp | email_server | 7.2.0 |
icewarp | email_server | 7.4.0 |
icewarp | email_server | 7.4.2 |
icewarp | email_server | 7.4.5 |
icewarp | email_server | 7.5.2 |
icewarp | email_server | 7.6.0 |
icewarp | email_server | 7.6.4 |
icewarp | email_server | 8.0.1 |
icewarp | email_server | 8.0.2 |
icewarp | email_server | 8.0.3 |
icewarp | email_server | 8.2.0 |
icewarp | email_server | 8.2.2 |
icewarp | email_server | 8.3.5 |
icewarp | email_server | 8.3.8 |
icewarp | email_server | 8.5.0 |
icewarp | email_server | 8.9.1 |
icewarp | email_server | 9.0.0 |
icewarp | email_server | 9.1.0 |
icewarp | email_server | 9.2.0 |
icewarp | webmail_server | 𝑥 ≤ 9.3.0 |
icewarp | webmail_server | 2.10.105 |
icewarp | webmail_server | 2.10.110 |
icewarp | webmail_server | 2.10.115 |
icewarp | webmail_server | 2.10.140 |
icewarp | webmail_server | 2.10.150 |
icewarp | webmail_server | 2.10.165 |
icewarp | webmail_server | 2.10.170 |
icewarp | webmail_server | 2.10.190 |
icewarp | webmail_server | 2.10.200 |
icewarp | webmail_server | 2.10.210 |
icewarp | webmail_server | 2.10.220 |
icewarp | webmail_server | 2.10.240 |
icewarp | webmail_server | 2.10.250 |
icewarp | webmail_server | 2.10.260 |
icewarp | webmail_server | 2.10.280 |
icewarp | webmail_server | 2.10.290 |
icewarp | webmail_server | 2.10.310 |
icewarp | webmail_server | 2.10.320 |
icewarp | webmail_server | 2.10.330 |
icewarp | webmail_server | 2.10.331 |
icewarp | webmail_server | 2.10.340 |
icewarp | webmail_server | 2.10.350 |
icewarp | webmail_server | 2.10.360 |
icewarp | webmail_server | 3.00.100 |
icewarp | webmail_server | 3.00.110 |
icewarp | webmail_server | 3.00.120 |
icewarp | webmail_server | 3.00.130 |
icewarp | webmail_server | 3.00.140 |
icewarp | webmail_server | 3.10.011 |
icewarp | webmail_server | 3.10.110 |
icewarp | webmail_server | 4.00.30 |
icewarp | webmail_server | 4.2.1 |
icewarp | webmail_server | 4.2.2 |
icewarp | webmail_server | 4.2.3 |
icewarp | webmail_server | 4.4.1 |
icewarp | webmail_server | 4.4.2 |
icewarp | webmail_server | 4.10.040 |
icewarp | webmail_server | 4.10.050 |
icewarp | webmail_server | 5.1.2 |
icewarp | webmail_server | 5.1.3 |
icewarp | webmail_server | 5.1.5 |
icewarp | webmail_server | 5.3.0 |
icewarp | webmail_server | 5.3.2 |
icewarp | webmail_server | 5.4.1 |
icewarp | webmail_server | 5.4.2 |
icewarp | webmail_server | 5.4.3 |
icewarp | webmail_server | 5.4.4 |
icewarp | webmail_server | 5.5.3 |
icewarp | webmail_server | 5.5.4 |
icewarp | webmail_server | 5.5.5 |
icewarp | webmail_server | 5.5.6 |
icewarp | webmail_server | 5.5.7 |
icewarp | webmail_server | 5.7.3 |
icewarp | webmail_server | 5.8.2 |
icewarp | webmail_server | 5.8.3 |
icewarp | webmail_server | 5.8.4 |
icewarp | webmail_server | 5.8.5 |
icewarp | webmail_server | 5.8.6 |
icewarp | webmail_server | 5.9.4 |
icewarp | webmail_server | 6.0.2 |
icewarp | webmail_server | 6.0.3 |
icewarp | webmail_server | 6.0.5 |
icewarp | webmail_server | 6.0.7 |
icewarp | webmail_server | 6.1.0 |
icewarp | webmail_server | 6.2.1 |
icewarp | webmail_server | 7.0.1 |
icewarp | webmail_server | 7.1.4 |
icewarp | webmail_server | 7.1.6 |
icewarp | webmail_server | 7.2.0 |
icewarp | webmail_server | 7.4.0 |
icewarp | webmail_server | 7.4.2 |
icewarp | webmail_server | 7.4.5 |
icewarp | webmail_server | 7.5.2 |
icewarp | webmail_server | 7.6.0 |
icewarp | webmail_server | 7.6.4 |
icewarp | webmail_server | 8.0.1 |
icewarp | webmail_server | 8.0.2 |
icewarp | webmail_server | 8.0.3 |
icewarp | webmail_server | 8.2.0 |
icewarp | webmail_server | 8.2.2 |
icewarp | webmail_server | 8.3.5 |
icewarp | webmail_server | 8.3.8 |
icewarp | webmail_server | 8.5.0 |
icewarp | webmail_server | 8.9.1 |
icewarp | webmail_server | 9.0.0 |
icewarp | webmail_server | 9.1.0 |
icewarp | webmail_server | 9.2.0 |
𝑥
= Vulnerable software versions
References