Neon WebMail For Java Multiple Input Validation Vulnerabilities
BID:20109
CVE-2006-4951 | CVE-2006-4952 | CVE-2006-4953 | CVE-2006-4954 | CVE-2006-4955 | CVE-2006-4956 |Info
Neon WebMail For Java Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 20109 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3320 CVE-2006-4953 CVE-2006-4956 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 20 2006 12:00AM |
| Updated: | Jul 05 2016 09:38PM |
| Credit: | Tan Chew Keong is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
NeoSys Neon Webmail for Java 5.07 (build.20060705 NeoSys Neon Webmail for Java 5.06 |
| Not Vulnerable: |
NeoSys Neon Webmail for Java 5.08 |
Discussion
Neon WebMail For Java Multiple Input Validation Vulnerabilities
Neon WebMail is prone to multiple input-validation vulnerabilities because it fails to sanitize user-supplied input. These issues include:
- an arbitrary-file-upload vulnerability
- an arbitrary-email-manipulation vulnerability
- multiple SQL-injection vulnerabilities
- an unauthorized-access vulnerability
- multiple directory-traversal vulnerabilities
- an HTML-injection vulnerability.
An attacker can exploit these issues to compromise the affected application.
Versions 5.06 and 5.07 (build.200607050) are vulnerable to these issue; prior versions may also be affected.
Neon WebMail is prone to multiple input-validation vulnerabilities because it fails to sanitize user-supplied input. These issues include:
- an arbitrary-file-upload vulnerability
- an arbitrary-email-manipulation vulnerability
- multiple SQL-injection vulnerabilities
- an unauthorized-access vulnerability
- multiple directory-traversal vulnerabilities
- an HTML-injection vulnerability.
An attacker can exploit these issues to compromise the affected application.
Versions 5.06 and 5.07 (build.200607050) are vulnerable to these issue; prior versions may also be affected.
Exploit / POC
Neon WebMail For Java Multiple Input Validation Vulnerabilities
An attacker can exploit these issues through a web-client.
The following proof-of-concept URIs are available:
An attacker can exploit these issues through a web-client.
The following proof-of-concept URIs are available:
Solution / Fix
Neon WebMail For Java Multiple Input Validation Vulnerabilities
Solution:
The vendor has released an update to address these issues. Please see the references for more information.
Solution:
The vendor has released an update to address these issues. Please see the references for more information.
References
Neon WebMail For Java Multiple Input Validation Vulnerabilities
References:
References:
- Neon Mail Home Page (NeoSys)
- Neon WebMail for Java Multiple Vulnerabilities (Tan Chew Keong)