.. / CVE-2019-12593

Exploit for IceWarp Mail Server <=10.4.4 - Local File Inclusion (CVE-2019-12593)

Description:

IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.

Nuclei Template

View the template here CVE-2019-12593.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2019/CVE-2019-12593.yaml
Copy

References:

http://www.icewarp.com
https://github.com/JameelNabbo/exploits/blob/master/IceWarp%20%3C%3D10.4.4%20local%20file%20include.txt
http://packetstormsecurity.com/files/153161/IceWarp-10.4.4-Local-File-Inclusion.html
https://nvd.nist.gov/vuln/detail/CVE-2019-12593
https://github.com/sobinge/nuclei-templates