Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) sql and (2) order_by elements in an XML search query.
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Email_server | Icewarp | * | 9.3.0 (including) |
Email_server | Icewarp | 2.10.105 (including) | 2.10.105 (including) |
Email_server | Icewarp | 2.10.110 (including) | 2.10.110 (including) |
Email_server | Icewarp | 2.10.115 (including) | 2.10.115 (including) |
Email_server | Icewarp | 2.10.140 (including) | 2.10.140 (including) |
Email_server | Icewarp | 2.10.150 (including) | 2.10.150 (including) |
Email_server | Icewarp | 2.10.165 (including) | 2.10.165 (including) |
Email_server | Icewarp | 2.10.170 (including) | 2.10.170 (including) |
Email_server | Icewarp | 2.10.190 (including) | 2.10.190 (including) |
Email_server | Icewarp | 2.10.200 (including) | 2.10.200 (including) |
Email_server | Icewarp | 2.10.210 (including) | 2.10.210 (including) |
Email_server | Icewarp | 2.10.220 (including) | 2.10.220 (including) |
Email_server | Icewarp | 2.10.240 (including) | 2.10.240 (including) |
Email_server | Icewarp | 2.10.250 (including) | 2.10.250 (including) |
Email_server | Icewarp | 2.10.260 (including) | 2.10.260 (including) |
Email_server | Icewarp | 2.10.280 (including) | 2.10.280 (including) |
Email_server | Icewarp | 2.10.290 (including) | 2.10.290 (including) |
Email_server | Icewarp | 2.10.310 (including) | 2.10.310 (including) |
Email_server | Icewarp | 2.10.320 (including) | 2.10.320 (including) |
Email_server | Icewarp | 2.10.330 (including) | 2.10.330 (including) |
Email_server | Icewarp | 2.10.331 (including) | 2.10.331 (including) |
Email_server | Icewarp | 2.10.340 (including) | 2.10.340 (including) |
Email_server | Icewarp | 2.10.350 (including) | 2.10.350 (including) |
Email_server | Icewarp | 2.10.360 (including) | 2.10.360 (including) |
Email_server | Icewarp | 3.00.100 (including) | 3.00.100 (including) |
Email_server | Icewarp | 3.00.110 (including) | 3.00.110 (including) |
Email_server | Icewarp | 3.00.120 (including) | 3.00.120 (including) |
Email_server | Icewarp | 3.00.130 (including) | 3.00.130 (including) |
Email_server | Icewarp | 3.00.140 (including) | 3.00.140 (including) |
Email_server | Icewarp | 3.10.011 (including) | 3.10.011 (including) |
Email_server | Icewarp | 3.10.110 (including) | 3.10.110 (including) |
Email_server | Icewarp | 4.00.30 (including) | 4.00.30 (including) |
Email_server | Icewarp | 4.2.1 (including) | 4.2.1 (including) |
Email_server | Icewarp | 4.2.2 (including) | 4.2.2 (including) |
Email_server | Icewarp | 4.2.3 (including) | 4.2.3 (including) |
Email_server | Icewarp | 4.4.1 (including) | 4.4.1 (including) |
Email_server | Icewarp | 4.4.2 (including) | 4.4.2 (including) |
Email_server | Icewarp | 4.10.040 (including) | 4.10.040 (including) |
Email_server | Icewarp | 4.10.050 (including) | 4.10.050 (including) |
Email_server | Icewarp | 5.1.2 (including) | 5.1.2 (including) |
Email_server | Icewarp | 5.1.3 (including) | 5.1.3 (including) |
Email_server | Icewarp | 5.1.5 (including) | 5.1.5 (including) |
Email_server | Icewarp | 5.3.0 (including) | 5.3.0 (including) |
Email_server | Icewarp | 5.3.2 (including) | 5.3.2 (including) |
Email_server | Icewarp | 5.4.1 (including) | 5.4.1 (including) |
Email_server | Icewarp | 5.4.2 (including) | 5.4.2 (including) |
Email_server | Icewarp | 5.4.3 (including) | 5.4.3 (including) |
Email_server | Icewarp | 5.4.4 (including) | 5.4.4 (including) |
Email_server | Icewarp | 5.5.3 (including) | 5.5.3 (including) |
Email_server | Icewarp | 5.5.4 (including) | 5.5.4 (including) |
Email_server | Icewarp | 5.5.5 (including) | 5.5.5 (including) |
Email_server | Icewarp | 5.5.6 (including) | 5.5.6 (including) |
Email_server | Icewarp | 5.5.7 (including) | 5.5.7 (including) |
Email_server | Icewarp | 5.7.3 (including) | 5.7.3 (including) |
Email_server | Icewarp | 5.8.2 (including) | 5.8.2 (including) |
Email_server | Icewarp | 5.8.3 (including) | 5.8.3 (including) |
Email_server | Icewarp | 5.8.4 (including) | 5.8.4 (including) |
Email_server | Icewarp | 5.8.5 (including) | 5.8.5 (including) |
Email_server | Icewarp | 5.8.6 (including) | 5.8.6 (including) |
Email_server | Icewarp | 5.9.4 (including) | 5.9.4 (including) |
Email_server | Icewarp | 6.0.2 (including) | 6.0.2 (including) |
Email_server | Icewarp | 6.0.3 (including) | 6.0.3 (including) |
Email_server | Icewarp | 6.0.5 (including) | 6.0.5 (including) |
Email_server | Icewarp | 6.0.7 (including) | 6.0.7 (including) |
Email_server | Icewarp | 6.1.0 (including) | 6.1.0 (including) |
Email_server | Icewarp | 6.2.1 (including) | 6.2.1 (including) |
Email_server | Icewarp | 7.0.1 (including) | 7.0.1 (including) |
Email_server | Icewarp | 7.1.4 (including) | 7.1.4 (including) |
Email_server | Icewarp | 7.1.6 (including) | 7.1.6 (including) |
Email_server | Icewarp | 7.2.0 (including) | 7.2.0 (including) |
Email_server | Icewarp | 7.4.0 (including) | 7.4.0 (including) |
Email_server | Icewarp | 7.4.2 (including) | 7.4.2 (including) |
Email_server | Icewarp | 7.4.5 (including) | 7.4.5 (including) |
Email_server | Icewarp | 7.5.2 (including) | 7.5.2 (including) |
Email_server | Icewarp | 7.6.0 (including) | 7.6.0 (including) |
Email_server | Icewarp | 7.6.4 (including) | 7.6.4 (including) |
Email_server | Icewarp | 8.0.1 (including) | 8.0.1 (including) |
Email_server | Icewarp | 8.0.2 (including) | 8.0.2 (including) |
Email_server | Icewarp | 8.0.3 (including) | 8.0.3 (including) |
Email_server | Icewarp | 8.2.0 (including) | 8.2.0 (including) |
Email_server | Icewarp | 8.2.2 (including) | 8.2.2 (including) |
Email_server | Icewarp | 8.3.5 (including) | 8.3.5 (including) |
Email_server | Icewarp | 8.3.8 (including) | 8.3.8 (including) |
Email_server | Icewarp | 8.5.0 (including) | 8.5.0 (including) |
Email_server | Icewarp | 8.9.1 (including) | 8.9.1 (including) |
Email_server | Icewarp | 9.0.0 (including) | 9.0.0 (including) |
Email_server | Icewarp | 9.1.0 (including) | 9.1.0 (including) |
Email_server | Icewarp | 9.2.0 (including) | 9.2.0 (including) |
Webmail_server | Icewarp | * | 9.3.0 (including) |
Webmail_server | Icewarp | 2.10.105 (including) | 2.10.105 (including) |
Webmail_server | Icewarp | 2.10.110 (including) | 2.10.110 (including) |
Webmail_server | Icewarp | 2.10.115 (including) | 2.10.115 (including) |
Webmail_server | Icewarp | 2.10.140 (including) | 2.10.140 (including) |
Webmail_server | Icewarp | 2.10.150 (including) | 2.10.150 (including) |
Webmail_server | Icewarp | 2.10.165 (including) | 2.10.165 (including) |
Webmail_server | Icewarp | 2.10.170 (including) | 2.10.170 (including) |
Webmail_server | Icewarp | 2.10.190 (including) | 2.10.190 (including) |
Webmail_server | Icewarp | 2.10.200 (including) | 2.10.200 (including) |
Webmail_server | Icewarp | 2.10.210 (including) | 2.10.210 (including) |
Webmail_server | Icewarp | 2.10.220 (including) | 2.10.220 (including) |
Webmail_server | Icewarp | 2.10.240 (including) | 2.10.240 (including) |
Webmail_server | Icewarp | 2.10.250 (including) | 2.10.250 (including) |
Webmail_server | Icewarp | 2.10.260 (including) | 2.10.260 (including) |
Webmail_server | Icewarp | 2.10.280 (including) | 2.10.280 (including) |
Webmail_server | Icewarp | 2.10.290 (including) | 2.10.290 (including) |
Webmail_server | Icewarp | 2.10.310 (including) | 2.10.310 (including) |
Webmail_server | Icewarp | 2.10.320 (including) | 2.10.320 (including) |
Webmail_server | Icewarp | 2.10.330 (including) | 2.10.330 (including) |
Webmail_server | Icewarp | 2.10.331 (including) | 2.10.331 (including) |
Webmail_server | Icewarp | 2.10.340 (including) | 2.10.340 (including) |
Webmail_server | Icewarp | 2.10.350 (including) | 2.10.350 (including) |
Webmail_server | Icewarp | 2.10.360 (including) | 2.10.360 (including) |
Webmail_server | Icewarp | 3.00.100 (including) | 3.00.100 (including) |
Webmail_server | Icewarp | 3.00.110 (including) | 3.00.110 (including) |
Webmail_server | Icewarp | 3.00.120 (including) | 3.00.120 (including) |
Webmail_server | Icewarp | 3.00.130 (including) | 3.00.130 (including) |
Webmail_server | Icewarp | 3.00.140 (including) | 3.00.140 (including) |
Webmail_server | Icewarp | 3.10.011 (including) | 3.10.011 (including) |
Webmail_server | Icewarp | 3.10.110 (including) | 3.10.110 (including) |
Webmail_server | Icewarp | 4.00.30 (including) | 4.00.30 (including) |
Webmail_server | Icewarp | 4.2.1 (including) | 4.2.1 (including) |
Webmail_server | Icewarp | 4.2.2 (including) | 4.2.2 (including) |
Webmail_server | Icewarp | 4.2.3 (including) | 4.2.3 (including) |
Webmail_server | Icewarp | 4.4.1 (including) | 4.4.1 (including) |
Webmail_server | Icewarp | 4.4.2 (including) | 4.4.2 (including) |
Webmail_server | Icewarp | 4.10.040 (including) | 4.10.040 (including) |
Webmail_server | Icewarp | 4.10.050 (including) | 4.10.050 (including) |
Webmail_server | Icewarp | 5.1.2 (including) | 5.1.2 (including) |
Webmail_server | Icewarp | 5.1.3 (including) | 5.1.3 (including) |
Webmail_server | Icewarp | 5.1.5 (including) | 5.1.5 (including) |
Webmail_server | Icewarp | 5.3.0 (including) | 5.3.0 (including) |
Webmail_server | Icewarp | 5.3.2 (including) | 5.3.2 (including) |
Webmail_server | Icewarp | 5.4.1 (including) | 5.4.1 (including) |
Webmail_server | Icewarp | 5.4.2 (including) | 5.4.2 (including) |
Webmail_server | Icewarp | 5.4.3 (including) | 5.4.3 (including) |
Webmail_server | Icewarp | 5.4.4 (including) | 5.4.4 (including) |
Webmail_server | Icewarp | 5.5.3 (including) | 5.5.3 (including) |
Webmail_server | Icewarp | 5.5.4 (including) | 5.5.4 (including) |
Webmail_server | Icewarp | 5.5.5 (including) | 5.5.5 (including) |
Webmail_server | Icewarp | 5.5.6 (including) | 5.5.6 (including) |
Webmail_server | Icewarp | 5.5.7 (including) | 5.5.7 (including) |
Webmail_server | Icewarp | 5.7.3 (including) | 5.7.3 (including) |
Webmail_server | Icewarp | 5.8.2 (including) | 5.8.2 (including) |
Webmail_server | Icewarp | 5.8.3 (including) | 5.8.3 (including) |
Webmail_server | Icewarp | 5.8.4 (including) | 5.8.4 (including) |
Webmail_server | Icewarp | 5.8.5 (including) | 5.8.5 (including) |
Webmail_server | Icewarp | 5.8.6 (including) | 5.8.6 (including) |
Webmail_server | Icewarp | 5.9.4 (including) | 5.9.4 (including) |
Webmail_server | Icewarp | 6.0.2 (including) | 6.0.2 (including) |
Webmail_server | Icewarp | 6.0.3 (including) | 6.0.3 (including) |
Webmail_server | Icewarp | 6.0.5 (including) | 6.0.5 (including) |
Webmail_server | Icewarp | 6.0.7 (including) | 6.0.7 (including) |
Webmail_server | Icewarp | 6.1.0 (including) | 6.1.0 (including) |
Webmail_server | Icewarp | 6.2.1 (including) | 6.2.1 (including) |
Webmail_server | Icewarp | 7.0.1 (including) | 7.0.1 (including) |
Webmail_server | Icewarp | 7.1.4 (including) | 7.1.4 (including) |
Webmail_server | Icewarp | 7.1.6 (including) | 7.1.6 (including) |
Webmail_server | Icewarp | 7.2.0 (including) | 7.2.0 (including) |
Webmail_server | Icewarp | 7.4.0 (including) | 7.4.0 (including) |
Webmail_server | Icewarp | 7.4.2 (including) | 7.4.2 (including) |
Webmail_server | Icewarp | 7.4.5 (including) | 7.4.5 (including) |
Webmail_server | Icewarp | 7.5.2 (including) | 7.5.2 (including) |
Webmail_server | Icewarp | 7.6.0 (including) | 7.6.0 (including) |
Webmail_server | Icewarp | 7.6.4 (including) | 7.6.4 (including) |
Webmail_server | Icewarp | 8.0.1 (including) | 8.0.1 (including) |
Webmail_server | Icewarp | 8.0.2 (including) | 8.0.2 (including) |
Webmail_server | Icewarp | 8.0.3 (including) | 8.0.3 (including) |
Webmail_server | Icewarp | 8.2.0 (including) | 8.2.0 (including) |
Webmail_server | Icewarp | 8.2.2 (including) | 8.2.2 (including) |
Webmail_server | Icewarp | 8.3.5 (including) | 8.3.5 (including) |
Webmail_server | Icewarp | 8.3.8 (including) | 8.3.8 (including) |
Webmail_server | Icewarp | 8.5.0 (including) | 8.5.0 (including) |
Webmail_server | Icewarp | 8.9.1 (including) | 8.9.1 (including) |
Webmail_server | Icewarp | 9.0.0 (including) | 9.0.0 (including) |
Webmail_server | Icewarp | 9.1.0 (including) | 9.1.0 (including) |
Webmail_server | Icewarp | 9.2.0 (including) | 9.2.0 (including) |
Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data. This can be used to alter query logic to bypass security checks, or to insert additional statements that modify the back-end database, possibly including execution of system commands. SQL injection has become a common issue with database-driven web sites. The flaw is easily detected, and easily exploited, and as such, any site or product package with even a minimal user base is likely to be subject to an attempted attack of this kind. This flaw depends on the fact that SQL makes no real distinction between the control and data planes.