CVE-2005-4558
Summary
| CVE | CVE-2005-4558 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-12-28 11:03:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL in a modified lang_settings parameter to mail/index.html. |
Risk And Classification
Primary CVSS: v2.0 6.5 from [email protected]
AV:N/AC:L/Au:S/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Deerfield | Visnetic Mail Server | 8.3.0_build1 | All | All | All |
| Application | Icewarp | Web Mail | 5.5.1 | All | All | All |
| Application | Merak | Mail Server | 8.3.0r | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Secunia - Advisories - VisNetic Mail Server Multiple Webmail Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| '[Full-disclosure] Secunia Research: IceWarp Web Mail Multiple File' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| IceWarp Universal WebMail Multiple Input Validation Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityTracker.com Archives - IceWarp Web Mail Multiple Include File Bugs Let Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| www.osvdb.org/22080 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| www.osvdb.org/22081 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Exploit, Vendor Advisory |
| Secunia - Advisories - IceWarp Web Mail Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Exploit, Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.