IceWarp Web Mail 5.5.1, as used by Merak Mail Server...
Vulnerability Description
IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL in a modified lang_settings parameter to mail/index.html.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-4558
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23904
- http://secunia.com/advisories/17865
- http://www.securityfocus.com/bid/16069
- http://secunia.com/advisories/17046
- http://securitytracker.com/id?1015412
- http://marc.info/?l=full-disclosure&m=113570229524828&w=2
- http://www.osvdb.org/22081
- http://secunia.com/secunia_research/2005-62/advisory/
- http://www.securityfocus.com/archive/1/420255/100/0/threaded
- http://www.osvdb.org/22080
More from deerfield
View All →Affected Vendor
deerfield
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.