7.5

CVE-2006-4951

Exploit
Neon WebMail for Java before 5.08 allows remote attackers to execute arbitrary Java (JSP) code by sending an e-mail message with a JSP file attachment, which is stored under the web root with a predictable filename.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NeosysNeon Webmail Version5.06 Editionjava
NeosysNeon Webmail Version5.07 Editionjava
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.54% 0.829
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/22029
Patch
Vendor Advisory
http://vuln.sg/neonmail506-en.html
Patch
Exploit
http://www.securityfocus.com/bid/20109
Patch
Exploit
http://www.securityfocus.com/bid/84198
https://exchange.xforce.ibmcloud.com/vulnerabilities/29086