NeoMail Neomail-prefs.PL Security Bypass Vulnerability
BID:16651
Info
NeoMail Neomail-prefs.PL Security Bypass Vulnerability
| Bugtraq ID: | 16651 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 14 2006 12:00AM |
| Updated: | Feb 15 2006 04:47PM |
| Credit: | This issue was disclosed by Tan Chew Keong of Secunia Research. |
| Vulnerable: |
Neocode Solutions Neomail 0 |
| Not Vulnerable: | |
Discussion
NeoMail Neomail-prefs.PL Security Bypass Vulnerability
NeoMail is prone to a vulnerability that bypasses security settings.
An attacker can exploit this issue to create and delete arbitrary user-account directories.
This may aid an attacker in further attacks, give users a false sense of security, and lead to loss of data integrity.
NeoMail is prone to a vulnerability that bypasses security settings.
An attacker can exploit this issue to create and delete arbitrary user-account directories.
This may aid an attacker in further attacks, give users a false sense of security, and lead to loss of data integrity.
Exploit / POC
NeoMail Neomail-prefs.PL Security Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
NeoMail Neomail-prefs.PL Security Bypass Vulnerability
Solution:
The vendor has addressed this issue in version 1.29; please see the reference section for further details.
Neocode Solutions Neomail 0
Solution:
The vendor has addressed this issue in version 1.29; please see the reference section for further details.
Neocode Solutions Neomail 0
-
Neocode Solutions neomail-1.29.tar.gz
Neomail 1.29
http://prdownloads.sourceforge.net/neomail/neomail-1.29.tar.gz
References
NeoMail Neomail-prefs.PL Security Bypass Vulnerability
References:
References:
- NeoMail upgrade to version 1.29 (NeoMail)