Back to Database
Status published
Medium
CVE-2011-3580
IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote...
Vulnerability Description
IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to obtain configuration information via a direct request to the /server URI, which triggers a call to the phpinfo function.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-3580
Credits & Attribution
No credits recorded in the NVD database.
References
- http://archives.neohapsis.com/archives/bugtraq/2011-09/0145.html
- http://www.securityfocus.com/bid/49753
- http://www.osvdb.org/75722
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70026
- https://www.trustwave.com/spiderlabs/advisories/TWSL2011-013.txt
- http://securityreason.com/securityalert/8404
- http://securitytracker.com/id?1026093
More from icewarp
View All →CVE-2022-35115
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was...
Critical
9.8
CVE-2021-36580
Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep...
Medium
6.1
CVE-2020-8512
In IceWarp Webmail Server through 11.4.4.1, there is XSS in...
Medium
6.1
CVE-2020-27982
IceWarp 11.4.5.0 allows XSS via the language parameter....
Medium
6.1
CVE-2020-25925
Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient...
Medium
6.1
Affected Vendor
icewarp
View all reports →Affected Software
mail server
Vulnerable Versions:
0, 9.3.0, 9.3.1, 9.3.2, 9.4.0, 9.4.1, 9.4.2, 10.0.3, 10.0.4, 10.0.7, 10.0.8, 10.1.1, 10.1.2, 10.1.3, 10.1.4, 10.2.0, 10.2.1, 10.2.2, 10.3.0, 10.3.1
Timeline
Official Publish:
September 30th, 2011
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.