5.5
CVE-2006-2308
- EPSS 1.61%
- Veröffentlicht 02.06.2006 00:02:00
- Zuletzt bearbeitet 16.06.2026 22:24:45
- Quelle PSIRT-CNA@flexerasoftware.com
- CVE-Watchlists
- Unerledigt
Directory traversal vulnerability in the IMAP service in EServ/3 3.25 allows remote authenticated users to read other user's email messages, create/rename arbitrary directories on the system, and delete empty directories via directory traversal sequences in the (1) CREATE, (2) SELECT, (3) DELETE, (4) RENAME, (5) COPY or (6) APPEND commands.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.61% | 0.728 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:P/I:P/A:N
|
http://secunia.com/advisories/20059
http://secunia.com/secunia_research/2006-37/advisory/
http://securityreason.com/securityalert/1006
http://www.eserv.ru/ru/news/news_detail.php?ID=235
http://www.securityfocus.com/archive/1/435415/100/0/threaded
http://www.securityfocus.com/bid/18179
http://www.vupen.com/english/advisories/2006/2066
https://exchange.xforce.ibmcloud.com/vulnerabilities/26738