Vulnerabilities > CVE-2006-4951 - Remote Security vulnerability in Neosys Neon Webmail 5.06/5.07

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
neosys

Summary

Neon WebMail for Java before 5.08 allows remote attackers to execute arbitrary Java (JSP) code by sending an e-mail message with a JSP file attachment, which is stored under the web root with a predictable filename.

Vulnerable Configurations

Part Description Count
Application
Neosys
2