Description
Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows remote attackers to include arbitrary files via a full Windows path and drive letter in the (1) language parameter in accounts/inc/include.php and (2) lang_settings parameter in admin/inc/include.php, which is not properly sanitized by the securepath function, a related issue to CVE-2005-4556.
Published: 2006-07-18
Score: 5.0 Medium
EPSS: 2.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2006-0823 Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows remote attackers to include arbitrary files via a full Windows path and drive letter in the (1) language parameter in accounts/inc/include.php and (2) lang_settings parameter in admin/inc/include.php, which is not properly sanitized by the securepath function, a related issue to CVE-2005-4556.
History

No history.

Subscriptions

Deerfield Visnetic Mail Server
Icewarp Web Mail
Merak Mail Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T16:48:56.454Z

Reserved: 2006-02-21T00:00:00.000Z

Link: CVE-2006-0817

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2006-07-21T14:03:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2006-0817

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses