Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-4558

Overview

Vulnerability Score 6.5 6.5
CVE Id CVE-2005-4558
Last Modified 05 Sep 2008 04:57:11
Published 28 Dec 2005 06:03:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2005-4558

Summary

IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL in a modified lang_settings parameter to mail/index.html.

Vulnerable Systems

Application

  • Deerfield Visnetic Mail Server 8.3.0 Build1

  • Icewarp Web Mail 5.5.1

  • Merak Mail Server 8.3.0r


References

SECUNIA - 17046

BID - 16069

BUGTRAQ - 20051227 Secunia Research: IceWarp Web Mail Multiple File InclusionVulnerabilities

MISC - http://secunia.com/secunia_research/2005-62/advisory/

XF - visnetic-settings-file-include(23904)

OSVDB - 22081

OSVDB - 22080

SECTRACK - 1015412

SECUNIA - 17865

FULLDISC - 20051227 Secunia Research: IceWarp Web Mail Multiple File


Last Updated: 27 May 2016 10:41:20