CVE-2006-0817: Medium severity Merak Mail Server vulnerability
Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows remote attackers to include arbitrary files via a full Windows path and drive letter in the (1) language parameter in accounts/inc/include.php and (2) langsettings parameter in admin/inc/include.php, which is not properly sanitized by the securepath function, a related issue to CVE-2005-4556.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0817?
CVE-2006-0817 is classified as a high severity vulnerability due to its potential for arbitrary file inclusion.
How do I fix CVE-2006-0817?
To fix CVE-2006-0817, upgrade to the latest versions of affected software, specifically Merak Mail Server 8.3.8r or later and VisNetic MailServer 8.5.0.5 or later.
Which software is affected by CVE-2006-0817?
CVE-2006-0817 affects Merak Mail Server versions 8.3.8r, IceWarp Web Mail version 5.6.0, and Deerfield Visnetic MailServer versions before 8.5.0.5.
What type of vulnerability is CVE-2006-0817?
CVE-2006-0817 is an absolute path directory traversal vulnerability that allows remote attackers to include arbitrary files.
Can I still use affected software versions if patched?
Even if a patch is applied, it is recommended to upgrade to the latest versions of the affected software to fully mitigate the risks associated with CVE-2006-0817.