PT-2006-2068 · Igenus · Igenus Webmail

Published

2006-03-07

·

Updated

2017-07-20

·

CVE-2006-1031

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions iGENUS Webmail versions 2.02 and earlier
Description The issue allows remote attackers to include arbitrary local files. This is achieved via the SG HOME parameter in the config/config inc.php file.
Recommendations For iGENUS Webmail versions 2.02 and earlier, consider restricting access to the SG HOME parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-1031

Affected Products

Igenus Webmail