CVE-2006-4954
Summary
| CVE | CVE-2006-4954 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-23 10:07:00 UTC |
| Updated | 2017-07-20 01:33:00 UTC |
| Description | The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile settings, and (4) creating and (5) deleting users. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Neosys | Neon Webmail | 5.06 | All | java | All |
| Application | Neosys | Neon Webmail | 5.07 | All | java | All |
| Application | Neosys | Neon Webmail | 5.06 | All | java | All |
| Application | Neosys | Neon Webmail | 5.07 | All | java | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Neon WebMail For Java Multiple Input Validation Vulnerabilities | BID | www.securityfocus.com | Exploit, Patch |
| Neon Webmail CVE-2006-4954 Remote Security Vulnerability | BID | www.securityfocus.com | |
| Neon WebMail for Java Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| [vuln.sg] Neon WebMail for Java Multiple Vulnerabilities | MISC | vuln.sg | Exploit, Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.