accountsettings_add.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allow remote attackers to create text files with arbitrary content via the accountid parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Web_mail | Icewarp | 3.3.2 (including) | 3.3.2 (including) |
Web_mail | Icewarp | 5.2.7 (including) | 5.2.7 (including) |
Web_mail | Icewarp | 5.2.8 (including) | 5.2.8 (including) |