← Vulnerability feed

Vulnerability record · CVE-2006-0817 · published 21 July 2006

CVE-2006-0817: Deerfield visnetic mail server vulnerability

Deerfield · Visnetic Mail Server

Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows remote attackers to include arbitrary files via a full Windows path and drive letter in the (1) language parameter in accounts/inc/include.php and (2) lang_settings parameter in admin/inc/include.php, which is not properly sanitized by the securepath function, a related issue to CVE-2005-4556.

5.0 CVSS 2.0 Medium EPSS 5.7% · top 7.3%
5.0CVSS 2.0 base score
5.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
28References, 10 tagged exploit
16 Jun 2026Last modified by NVD

Description

Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows remote attackers to include arbitrary files via a full Windows path and drive letter in the (1) language parameter in accounts/inc/include.php and (2) lang_settings parameter in admin/inc/include.php, which is not properly sanitized by the securepath function, a related issue to CVE-2005-4556.

AV:N/AC:L/Au:N/C:N/I:P/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/18953 ExploitPatchVendor Advisory
http://secunia.com/advisories/18966 ExploitPatchVendor Advisory
http://secunia.com/secunia_research/2006-12/advisory/ ExploitVendor Advisory
http://secunia.com/secunia_research/2006-14/advisory/ ExploitVendor Advisory
http://securitytracker.com/id?1016513
http://securitytracker.com/id?1016514
http://www.osvdb.org/27328
http://www.securityfocus.com/archive/1/440297/100/0/threaded
http://www.securityfocus.com/archive/1/440302/100/0/threaded
http://www.securityfocus.com/bid/19002 ExploitPatch
http://www.securityfocus.com/bid/19007
http://www.vupen.com/english/advisories/2006/2825
http://www.vupen.com/english/advisories/2006/2826
https://exchange.xforce.ibmcloud.com/vulnerabilities/27773
http://secunia.com/advisories/18953 ExploitPatchVendor Advisory
http://secunia.com/advisories/18966 ExploitPatchVendor Advisory
http://secunia.com/secunia_research/2006-12/advisory/ ExploitVendor Advisory
http://secunia.com/secunia_research/2006-14/advisory/ ExploitVendor Advisory
http://securitytracker.com/id?1016513
http://securitytracker.com/id?1016514
http://www.osvdb.org/27328
http://www.securityfocus.com/archive/1/440297/100/0/threaded
http://www.securityfocus.com/archive/1/440302/100/0/threaded
http://www.securityfocus.com/bid/19002 ExploitPatch
http://www.securityfocus.com/bid/19007
http://www.vupen.com/english/advisories/2006/2825
http://www.vupen.com/english/advisories/2006/2826
https://exchange.xforce.ibmcloud.com/vulnerabilities/27773

Track CVE-2006-0817 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2005-4556Deerfield visnetic mail server vulnerabilityPHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, …EPSS 11%7.5CVE-2004-1672Icewarp web mail vulnerabilityattachment.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to view other users' attac…EPSS 1.7%7.5CVE-2004-1673Icewarp web mail vulnerabilityaccountsettings_add.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allow remote attackers to create text fil…EPSS 1.7%7.5CVE-2004-1674Icewarp web mail vulnerabilityviewaction.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to (1) delete arbitrary fi…EPSS 1.5%7.5CVE-2004-1670Icewarp web mail vulnerabilityMultiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers…EPSS 1.8%7.5CVE-2004-1722Merak mail server vulnerabilitySQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule …EPSS 2.7%7.5CVE-2002-0258Icewarp web mail vulnerabilityMerak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers wi…EPSS 1.4%7.2CVE-2005-0322Icewarp web mail vulnerabilityMERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encryption in the (1) users.cfg, …EPSS 0.24%

Source: NIST National Vulnerability Database (record CVE-2006-0817), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.