
CVE-2006-2484
https://notcve.org/view.php?id=CVE-2006-2484
19 May 2006 — Cross-site scripting (XSS) vulnerability in index.html in IceWarp WebMail 5.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the PHPSESSID parameter. • http://securityreason.com/securityalert/925 •

CVE-2005-0321
https://notcve.org/view.php?id=CVE-2005-0321
10 Feb 2005 — MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allows remote authenticated users to gain sensitive information via an HTTP request to (1) calendar_d.html, (2) calendar_m.html, (3) calendar_w.html, or (4) calendar_y.html, which reveal the installation path. • http://marc.info/?l=bugtraq&m=110693950205007&w=2 •

CVE-2005-0322
https://notcve.org/view.php?id=CVE-2005-0322
10 Feb 2005 — MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encryption in the (1) users.cfg, (2) settings.cfg, (3) users.dat or (4) user.dat files, which allows local users to extract the passwords. • http://marc.info/?l=bugtraq&m=110693950205007&w=2 •

CVE-2005-0320 – IceWarp Web Mail 5.3 - 'accountsettings_add.html?accountid' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2005-0320
28 Jan 2005 — Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) note, (4) title, and (5) location fields to calendar.html. • https://www.exploit-db.com/exploits/25069 •