5
CVE-2006-2414
- EPSS 2.39%
- Veröffentlicht 16.05.2006 10:02:00
- Zuletzt bearbeitet 16.06.2026 22:24:57
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the (1) LIST or (2) DELETE IMAP command.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Timo Sirainen ≫ Dovecot Version1.0
Timo Sirainen ≫ Dovecot Version1.0_beta2
Timo Sirainen ≫ Dovecot Version1.0_beta3
Timo Sirainen ≫ Dovecot Version1.0_beta7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.39% | 0.818 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://dovecot.org/list/dovecot-cvs/2006-May/005563.html
http://secunia.com/advisories/20308
http://secunia.com/advisories/20315
http://securityreason.com/securityalert/913
http://www.debian.org/security/2006/dsa-1080
http://www.dovecot.org/list/dovecot-news/2006-May/000006.html
http://www.securityfocus.com/archive/1/433878/100/0/threaded
http://www.securityfocus.com/bid/17961
http://www.vupen.com/english/advisories/2006/2013
https://exchange.xforce.ibmcloud.com/vulnerabilities/26536