Vulnerabilities > Merak > Mail Server > 8.2.4r

DATE CVE VULNERABILITY TITLE RISK
2005-10-04 CVE-2005-3133 Directory Traversal vulnerability in IceWarp Web Mail
Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to (1) delete arbitrary files or directories via a relative path to the id parameter to logout.html or (2) include arbitrary PHP files or other files via the helpid parameter to help.html.
network
low complexity
icewarp merak
5.0
2005-10-04 CVE-2005-3132 Information Disclosure vulnerability in Web Mail
MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to bwlist_inc.html, which reveals the path in an error message.
network
low complexity
icewarp merak
5.0
2005-10-04 CVE-2005-3131 Cross-Site Scripting vulnerability in IceWarp
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html.
network
icewarp merak
4.3