Summary
The remote webmail server is affected by multiple vulnerabilities which may allow an attacker to execute arbitrary commands on the remote host.
Description:
The remote host is running VisNetic / Merak Mail Server, a multi-featured mail server for Windows.
The webmail and webadmin services included in the remote version of this software are prone to multiple flaws. An attacker could send specially-crafted URLs to execute arbitrary scripts, perhaps taken from third-party hosts, or to disclose the content of files on the remote system.
Solution
Upgrade to Merak Mail Server 8.3.5.r / VisNetic Mail Server version 8.3.5 or later.
References
Updated on 2017-03-28
Severity
Classification
-
CVE CVE-2005-4556, CVE-2005-4557, CVE-2005-4558, CVE-2005-4559 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities