First published: Wed Dec 28 2005(Updated: )
IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL in a modified lang_settings parameter to mail/index.html.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Deerfield Visnetic Mail Server | =8.3.0_build1 | |
Merak Mail Server | =8.3.0r | |
IceWarp Web Mail | =5.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.