MEDIUM · 5.0

CVE-2005-4559

mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and layout_settings var...

Vulnerability Description

mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and layout_settings variables when an unrecognized HTTP_USER_AGENT string is provided, which allows remote attackers to access arbitrary files via a request with an unrecognized User Agent that also specifies the desired default_layout and layout_settings parameters.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
DeerfieldVisnetic Mail Server8.3.0_build1
IcewarpWeb Mail5.5.1
MerakMail Server8.3.0r

References

FAQ

What is CVE-2005-4559?

CVE-2005-4559 is a vulnerability with a CVSS score of 5.0 (MEDIUM). mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and layout_settings var...

How severe is CVE-2005-4559?

CVE-2005-4559 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-4559?

Check the references section above for vendor advisories and patch information. Affected products include: Deerfield Visnetic Mail Server, Icewarp Web Mail, Merak Mail Server.