peter bassill · operator
$ cve CVE-2005-4558 JSON

CVE-2005-4558 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 8.5% (pctl 95)

Patch early

A public exploit exists.

Description

IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL in a modified lang_settings parameter to mail/index.html.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS8.49% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2005-12-28
Last modified2026-06-16

Affected (3)

VendorProduct
deerfieldvisnetic mail server
icewarpweb mail
merakmail server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD