peter bassill · operator
$ cve CVE-2005-4556 JSON

CVE-2005-4556 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 10.6% (pctl 96)

Patch early

A public exploit exists.

Description

PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote attackers to include arbitrary local and remote PHP files via a URL in the (1) lang_settings and (2) language parameters in (a) accounts/inc/include.php and (b) admin/inc/include.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS10.57% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2005-12-28
Last modified2026-06-16

Affected (3)

VendorProduct
deerfieldvisnetic mail server
icewarpweb mail
merakmail server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD