First published: Wed Dec 28 2005(Updated: )
PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote attackers to include arbitrary local and remote PHP files via a URL in the (1) lang_settings and (2) language parameters in (a) accounts/inc/include.php and (b) admin/inc/include.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Deerfield Visnetic Mail Server | =8.3.0_build1 | |
IceWarp WebMail Server | =5.5.1 | |
IceWarp Merak Mail Server | =8.3.0r |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4556 has a high severity rating as it allows remote code execution if exploited.
To fix CVE-2005-4556, disable register_globals in your PHP configuration or apply a patch provided by the vendor.
CVE-2005-4556 affects IceWarp Web Mail 5.5.1, Merak Mail Server 8.3.0r, and VisNetic Mail Server 8.3.0 build 1.
Yes, exploitation of CVE-2005-4556 may lead to unauthorized access and potential data loss.
A temporary workaround for CVE-2005-4556 is to limit PHP file inclusion to trusted sources until a full fix can be applied.