Absolute path directory traversal vulnerability in (a) MERAK Mail Server...
Vulnerability Description
Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows remote attackers to include arbitrary files via a full Windows path and drive letter in the (1) language parameter in accounts/inc/include.php and (2) lang_settings parameter in admin/inc/include.php, which is not properly sanitized by the securepath function, a related issue to CVE-2005-4556.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-0817
Credits & Attribution
No credits recorded in the NVD database.
References
- http://securitytracker.com/id?1016514
- http://www.securityfocus.com/bid/19002
- http://securitytracker.com/id?1016513
- http://secunia.com/advisories/18966
- http://secunia.com/advisories/18953
- http://www.securityfocus.com/archive/1/440302/100/0/threaded
- http://www.osvdb.org/27328
- http://secunia.com/secunia_research/2006-12/advisory/
- http://secunia.com/secunia_research/2006-14/advisory/
- http://www.securityfocus.com/archive/1/440297/100/0/threaded
- http://www.vupen.com/english/advisories/2006/2826
- http://www.vupen.com/english/advisories/2006/2825
- http://www.securityfocus.com/bid/19007
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27773
More from deerfield
View All →Affected Vendor
deerfield
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.