Vulnerabilities > CVE-2006-4954 - Unspecified vulnerability in Neosys Neon Webmail 5.06/5.07

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
neosys
exploit available

Summary

The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile settings, and (4) creating and (5) deleting users.

Vulnerable Configurations

Part Description Count
Application
Neosys
2

Exploit-Db

descriptionNeoSys Neon Webmail for Java 5.06/5.07 updateuser Servlet in_id Variable Arbitrary User Information Modification. CVE-2006-4954 . Webapps exploit for jsp pla...
idEDB-ID:28609
last seen2016-02-03
modified2006-09-20
published2006-09-20
reporterTan Chew Keong
sourcehttps://www.exploit-db.com/download/28609/
titleNeoSys Neon Webmail for Java 5.06/5.07 updateuser Servlet in_id Variable Arbitrary User Information Modification