Lucene search

K
cveMitreCVE-2005-4558
HistoryDec 28, 2005 - 11:03 a.m.

CVE-2005-4558

2005-12-2811:03:00
mitre
web.nvd.nist.gov
41
cve-2005-4558
icewarp
web mail
merak mail server
visnetic mail server
security vulnerability
php code
language parameter

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0.118

Percentile

95.3%

IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL in a modified lang_settings parameter to mail/index.html.

Affected configurations

Nvd
Node
deerfieldvisnetic_mail_serverMatch8.3.0_build1
OR
icewarpweb_mailMatch5.5.1
OR
merakmail_serverMatch8.3.0r
VendorProductVersionCPE
deerfieldvisnetic_mail_server8.3.0_build1cpe:2.3:a:deerfield:visnetic_mail_server:8.3.0_build1:*:*:*:*:*:*:*
icewarpweb_mail5.5.1cpe:2.3:a:icewarp:web_mail:5.5.1:*:*:*:*:*:*:*
merakmail_server8.3.0rcpe:2.3:a:merak:mail_server:8.3.0r:*:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0.118

Percentile

95.3%