S4E just found a medium-severity finding from host header injection vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2015-1503 Scanner

CVE-2015-1503 scanner - Directory Traversal vulnerability in IceWarp Mail Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2015-1503
7.5
CVSS

Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot) in the (2) script or (3) style parameter to webmail/old/calendar/minimizer/index.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

IceWarp Mail Server is a mail server software that supports email, calendar, and collaboration features. It is designed to provide a secure and reliable platform for businesses and organizations to communicate with their clients and employees. It is used by companies of all sizes to manage their email and communication needs and streamline their workflow.

One of the vulnerabilities in IceWarp Mail Server is CVE-2015-1503. This vulnerability is caused by multiple directory traversal weaknesses that can be exploited by remote attackers. Hackers can use ".." (dot dot) or ".../." (dot dot dot slash dot) to read arbitrary files. This vulnerability is present on the webmail/client/skins/default/css/css.php page and the webmail/old/calendar/minimizer/index.php page on versions of IceWarp Mail Server before 11.2.

Exploiting CVE-2015-1503 allows attackers to access sensitive data, such as usernames, passwords, and other confidential information. Attackers can also install malicious code on servers, which can be used for further attacks. These types of attacks can lead to serious consequences, including data breaches, identity thefts, and financial thefts.

In conclusion, keeping your digital assets secure is crucial in today's ever-evolving threat landscape. s4e.io offers a comprehensive and easy-to-use platform that enables users to quickly and accurately assess their cybersecurity posture. With its pro features, users can easily identify vulnerabilities in their digital assets and take proactive measures to defend against cyber attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability in IceWarp Mail Server, users should apply the following precautions:

  • Update to the latest version of IceWarp Mail Server to fix the vulnerability.
  • Monitor web server logs and check for any suspicious activity.
  • Restrict access to the webmail/client/skins/default/css/css.php and webmail/old/calendar/minimizer/index.php pages.
  • Use a secure password policy and perform regular password changes.
  • Educate users on the risks of phishing and social engineering attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2015-1503 scanner - Directory Traversal vulnerability in IceWarp Mail Server | S4E