5

CVE-2006-0711

The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NeomailNeomail Version <= 1.28
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.49% 0.708
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/18785
Patch
Vendor Advisory
http://secunia.com/secunia_research/2006-3/advisory/
Vendor Advisory
http://sourceforge.net/project/shownotes.php?release_id=392562&group_id=2874
Patch
http://www.securityfocus.com/bid/16651
http://www.vupen.com/english/advisories/2006/0564
https://exchange.xforce.ibmcloud.com/vulnerabilities/24737