CVE-2005-4556
PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote attackers to include arbitrary local and remote PHP…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote attackers to include arbitrary local and remote PHP files via a URL in the (1) lang_settings and (2) language parameters in (a) accounts/inc/include.php and (b) admin/inc/include.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 10.57% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- deerfield/visnetic mail server · icewarp/web mail · merak/mail server
- Source
- cve@mitre.org
References
- http://marc.info/?l=full-disclosure&m=113570229524828&w=2
- http://secunia.com/advisories/17046Exploit, Patch, Vendor Advisory
- http://secunia.com/advisories/17865
- http://secunia.com/secunia_research/2005-62/advisory/Exploit, Vendor Advisory
- http://securitytracker.com/id?1015412
- http://www.osvdb.org/22077
- http://www.osvdb.org/22078
- http://www.securityfocus.com/archive/1/420255/100/0/threaded
- http://www.securityfocus.com/bid/16069Exploit
- http://marc.info/?l=full-disclosure&m=113570229524828&w=2
- http://secunia.com/advisories/17046Exploit, Patch, Vendor Advisory
- http://secunia.com/advisories/17865
- http://secunia.com/secunia_research/2005-62/advisory/Exploit, Vendor Advisory
- http://securitytracker.com/id?1015412
- http://www.osvdb.org/22077
- http://www.osvdb.org/22078
- http://www.securityfocus.com/archive/1/420255/100/0/threaded
- http://www.securityfocus.com/bid/16069Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.