Symantec Vulnerability Research SYMSA-2006-010: The web server under IronWebMail employs a simple macro language for evaluating pathname references. A loss of confidentiality occurs as a result of faulty pathname evaluation, causing unauthenticated access violation.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/51136/SYMSA-2006-010.txt
Source: https://packetstormsecurity.com/files/51136/SYMSA-2006-010.txt.html

