PT-2006-1026 · Ingo · Ingo H3

Michael Menge

·

Publicado

2006-10-23

·

Atualizado

2011-03-08

·

CVE-2006-5449

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Ingo H3 versions prior to 1.1.2
Description: The issue allows remote authenticated users to execute arbitrary commands via shell metacharacters in the mailbox destination of a filter rule. Multiple vulnerabilities in the ingo1 package may lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited by a remote attacker who has passed the authentication procedure.
Recommendations: For Ingo H3 versions prior to 1.1.2, update to version 1.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to filter rules to minimize the risk of exploitation. Avoid using shell metacharacters in the mailbox destination of filter rules until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-03438
CVE-2006-5449
DSA-1204-1

Produtos afetados

Ingo H3