PT-2006-1026 · Ingo · Ingo H3
Michael Menge
·
Published
2006-10-23
·
Updated
2011-03-08
·
CVE-2006-5449
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Ingo H3 versions prior to 1.1.2
Description:
The issue allows remote authenticated users to execute arbitrary commands via shell metacharacters in the mailbox destination of a filter rule. Multiple vulnerabilities in the ingo1 package may lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited by a remote attacker who has passed the authentication procedure.
Recommendations:
For Ingo H3 versions prior to 1.1.2, update to version 1.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to filter rules to minimize the risk of exploitation. Avoid using shell metacharacters in the mailbox destination of filter rules until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ingo H3