Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-4558

Опубликовано: 28 дек. 2005
Источник: nvd
CVSS2: 6.5
EPSS Средний

Описание

IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL in a modified lang_settings parameter to mail/index.html.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:deerfield:visnetic_mail_server:8.3.0_build1:*:*:*:*:*:*:*
cpe:2.3:a:icewarp:web_mail:5.5.1:*:*:*:*:*:*:*
cpe:2.3:a:merak:mail_server:8.3.0r:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.11946
Средний

6.5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL in a modified lang_settings parameter to mail/index.html.

EPSS

Процентиль: 94%
0.11946
Средний

6.5 Medium

CVSS2

Дефекты

NVD-CWE-Other