PT-2006-1764 · Neomail · Neomail

Published

2006-02-15

·

Updated

2017-07-20

·

CVE-2006-0711

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions NeoMail version 1.28
Description The issue concerns the addfolder and deletefolder functions in neomail-prefs.pl, which fail to validate the Session ID. This allows remote attackers to add and delete arbitrary files when NeoMail is configured with homedirfolders and homedirspools disabled.
Recommendations For NeoMail version 1.28, as a temporary workaround, consider disabling the addfolder and deletefolder functions until a patch is available. Restrict access to the neomail-prefs.pl script to minimize the risk of exploitation. Avoid using the Session ID parameter in the affected functions until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0711

Affected Products

Neomail