CVE-2011-3579
MEDIUM 6.4EPSS 4.8%
server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference.
- CVSS v2.0
- 6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:P - EPSS
- 4.78% chance of exploitation in the next 30 days, 91th percentile
- Published
- 2011-09-30
- Updated
- 2024-08-06