PT-2006-1026 · Ingo · Ingo H3

Michael Menge

·

Published

2006-10-23

·

Updated

2011-03-08

·

CVE-2006-5449

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Ingo H3 versions prior to 1.1.2
Description: The issue allows remote authenticated users to execute arbitrary commands via shell metacharacters in the mailbox destination of a filter rule. Multiple vulnerabilities in the ingo1 package may lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited by a remote attacker who has passed the authentication procedure.
Recommendations: For Ingo H3 versions prior to 1.1.2, update to version 1.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to filter rules to minimize the risk of exploitation. Avoid using shell metacharacters in the mailbox destination of filter rules until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03438
CVE-2006-5449
DSA-1204-1

Affected Products

Ingo H3