Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2005-4558
Description:IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL in a modified lang_settings parameter to mail/index.html.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2005-4558
BugTraq ID: 16069
http://www.securityfocus.com/bid/16069
Bugtraq: 20051227 Secunia Research: IceWarp Web Mail Multiple File InclusionVulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/420255/100/0/threaded
http://marc.info/?l=full-disclosure&m=113570229524828&w=2
http://secunia.com/secunia_research/2005-62/advisory/
http://www.osvdb.org/22080
http://www.osvdb.org/22081
http://securitytracker.com/id?1015412
http://secunia.com/advisories/17046
http://secunia.com/advisories/17865
XForce ISS Database: visnetic-settings-file-include(23904)
https://exchange.xforce.ibmcloud.com/vulnerabilities/23904




© 1998-2025 E-Soft Inc. All rights reserved.