VYPR
Unrated severityNVD Advisory· Published Dec 28, 2005· Updated Jun 16, 2026

CVE-2005-4559

CVE-2005-4559

Description

mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and layout_settings variables when an unrecognized HTTP_USER_AGENT string is provided, which allows remote attackers to access arbitrary files via a request with an unrecognized User Agent that also specifies the desired default_layout and layout_settings parameters.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:deerfield:visnetic_mail_server:8.3.0_build1:*:*:*:*:*:*:*
  • IceWarp/WebMail2 versions
    cpe:2.3:a:icewarp:web_mail:5.5.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:icewarp:web_mail:5.5.1:*:*:*:*:*:*:*
    • (no CPE)range: = 5.5.1
  • Merak/Mail Server2 versions
    cpe:2.3:a:merak:mail_server:8.3.0r:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:merak:mail_server:8.3.0r:*:*:*:*:*:*:*
    • (no CPE)range: = 8.3.0r
  • Range: = 8.3.0 build 1

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.