CVE-2005-4556
EXPLOITEDVisNetic Mail Server 8.3.0 build 1 - Remote File Inclusion via lang_settings or language Parameter
Title source: llmExploitation Summary
CVE-2005-4556 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including Tan Chew Keong.
AI-analyzed exploit summary The provided text describes a file inclusion vulnerability in IceWarp Universal WebMail, integrated into Deerfield VisNetic Mail Server and Merak Mail Server. It allows arbitrary local or remote file inclusion, leading to potential RCE or information disclosure.
Description
PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote attackers to include arbitrary local and remote PHP files via a URL in the (1) lang_settings and (2) language parameters in (a) accounts/inc/include.php and (b) admin/inc/include.php.
Exploits (2)
The provided text describes a file inclusion vulnerability in IceWarp Universal WebMail, integrated into Deerfield VisNetic Mail Server and Merak Mail Server. It allows arbitrary local or remote file inclusion, leading to potential RCE or information disclosure.
The exploit describes a file inclusion vulnerability in IceWarp Universal WebMail, allowing arbitrary local or remote file inclusion via the 'language' and 'lang_settings' parameters. This can lead to remote code execution or information disclosure.