Vulnerabilities > CVE-2006-4952 - Remote Security vulnerability in Neosys Neon Webmail 5.06/5.07

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
neosys
exploit available

Summary

The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail folders, specified by the folderid and tofolderid parameters, via the ID parameter.

Vulnerable Configurations

Part Description Count
Application
Neosys
2

Exploit-Db

descriptionNeoSys Neon Webmail for Java 5.06/5.07 updatemail Servlet Arbitrary Mail Message Manipulation. CVE-2006-4952. Webapps exploit for jsp platform
idEDB-ID:28606
last seen2016-02-03
modified2006-09-20
published2006-09-20
reporterTan Chew Keong
sourcehttps://www.exploit-db.com/download/28606/
titleNeoSys Neon Webmail for Java 5.06/5.07 updatemail Servlet Arbitrary Mail Message Manipulation