CVE-2006-0817

Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows remote attackers to include arbitrary files via a full Windows path and drive letter in the (1) language parameter in accounts/inc/include.php and (2) lang_settings parameter in admin/inc/include.php, which is not properly sanitized by the securepath function, a related issue to CVE-2005-4556.
References
Link Resource
http://secunia.com/advisories/18953 Exploit Patch Vendor Advisory
http://secunia.com/advisories/18966 Exploit Patch Vendor Advisory
http://secunia.com/secunia_research/2006-12/advisory/ Exploit Vendor Advisory
http://secunia.com/secunia_research/2006-14/advisory/ Exploit Vendor Advisory
http://securitytracker.com/id?1016513
http://securitytracker.com/id?1016514
http://www.osvdb.org/27328
http://www.securityfocus.com/archive/1/440297/100/0/threaded
http://www.securityfocus.com/archive/1/440302/100/0/threaded
http://www.securityfocus.com/bid/19002 Exploit Patch
http://www.securityfocus.com/bid/19007
http://www.vupen.com/english/advisories/2006/2825
http://www.vupen.com/english/advisories/2006/2826
https://exchange.xforce.ibmcloud.com/vulnerabilities/27773
http://secunia.com/advisories/18953 Exploit Patch Vendor Advisory
http://secunia.com/advisories/18966 Exploit Patch Vendor Advisory
http://secunia.com/secunia_research/2006-12/advisory/ Exploit Vendor Advisory
http://secunia.com/secunia_research/2006-14/advisory/ Exploit Vendor Advisory
http://securitytracker.com/id?1016513
http://securitytracker.com/id?1016514
http://www.osvdb.org/27328
http://www.securityfocus.com/archive/1/440297/100/0/threaded
http://www.securityfocus.com/archive/1/440302/100/0/threaded
http://www.securityfocus.com/bid/19002 Exploit Patch
http://www.securityfocus.com/bid/19007
http://www.vupen.com/english/advisories/2006/2825
http://www.vupen.com/english/advisories/2006/2826
https://exchange.xforce.ibmcloud.com/vulnerabilities/27773
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:deerfield:visnetic_mail_server:8.3.5:*:*:*:*:*:*:*
cpe:2.3:a:icewarp:web_mail:5.6.0:*:*:*:*:*:*:*
cpe:2.3:a:merak:mail_server:8.3.8r:*:windows:*:*:*:*:*

History

21 Nov 2024, 00:07

Type Values Removed Values Added
References () http://secunia.com/advisories/18953 - Exploit, Patch, Vendor Advisory () http://secunia.com/advisories/18953 - Exploit, Patch, Vendor Advisory
References () http://secunia.com/advisories/18966 - Exploit, Patch, Vendor Advisory () http://secunia.com/advisories/18966 - Exploit, Patch, Vendor Advisory
References () http://secunia.com/secunia_research/2006-12/advisory/ - Exploit, Vendor Advisory () http://secunia.com/secunia_research/2006-12/advisory/ - Exploit, Vendor Advisory
References () http://secunia.com/secunia_research/2006-14/advisory/ - Exploit, Vendor Advisory () http://secunia.com/secunia_research/2006-14/advisory/ - Exploit, Vendor Advisory
References () http://securitytracker.com/id?1016513 - () http://securitytracker.com/id?1016513 -
References () http://securitytracker.com/id?1016514 - () http://securitytracker.com/id?1016514 -
References () http://www.osvdb.org/27328 - () http://www.osvdb.org/27328 -
References () http://www.securityfocus.com/archive/1/440297/100/0/threaded - () http://www.securityfocus.com/archive/1/440297/100/0/threaded -
References () http://www.securityfocus.com/archive/1/440302/100/0/threaded - () http://www.securityfocus.com/archive/1/440302/100/0/threaded -
References () http://www.securityfocus.com/bid/19002 - Exploit, Patch () http://www.securityfocus.com/bid/19002 - Exploit, Patch
References () http://www.securityfocus.com/bid/19007 - () http://www.securityfocus.com/bid/19007 -
References () http://www.vupen.com/english/advisories/2006/2825 - () http://www.vupen.com/english/advisories/2006/2825 -
References () http://www.vupen.com/english/advisories/2006/2826 - () http://www.vupen.com/english/advisories/2006/2826 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27773 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27773 -

Information

Published : 2006-07-21 14:03

Updated : 2024-11-21 00:07


NVD link : CVE-2006-0817

Mitre link : CVE-2006-0817

CVE.ORG link : CVE-2006-0817


JSON object : View

Products Affected

icewarp

  • web_mail

deerfield

  • visnetic_mail_server

merak

  • mail_server