CVE-2006-0757
Summary
| CVE | CVE-2006-0757 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-02-18 02:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters in (4) calendar.event.php, (5) index.php, (6) pop.download.php, (7) read.bounce.php, (8) rules.block.php, (9) language.php, and (10) certain other scripts, as demonstrated by an addressbook.update.php request with a contactgroupid value of phpinfo() preceded by facilitators. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS: 0.078800000 probability, percentile 0.920340000 (date 2026-04-16)
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hivemail | Hivemail | 1.1 | All | All | All |
| Application | Hivemail | Hivemail | 1.1.1 | All | All | All |
| Application | Hivemail | Hivemail | 1.2 | All | All | All |
| Application | Hivemail | Hivemail | 1.2.1_beta1 | All | All | All |
| Application | Hivemail | Hivemail | 1.2.1_rc | All | All | All |
| Application | Hivemail | Hivemail | 1.2.2 | All | All | All |
| Application | Hivemail | Hivemail | 1.2_sp1 | All | All | All |
| Application | Hivemail | Hivemail | 1.3 | All | All | All |
| Application | Hivemail | Hivemail | 1.3_beta1 | All | All | All |
| Application | Hivemail | Hivemail | 1.3_rc1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| HiveMail Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| HiveMail Remote Code Execution Vulnerabilities - HiveMail Forums | af854a3a-2127-422b-91ae-364da2661108 | forum.hivemail.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Contact Support | af854a3a-2127-422b-91ae-364da2661108 | www.gulftech.org | Vendor Advisory |
| Multiple HiveMail Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| archives.neohapsis.com/archives/bugtraq/2006-02/0162.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.