CVE-2006-0711

The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:neomail:neomail:*:*:*:*:*:*:*:*

Information

Published : 2006-02-15 03:06

Updated : 2017-07-19 18:30


NVD link : CVE-2006-0711

Mitre link : CVE-2006-0711


JSON object : View

Advertisement

dedicated server usa

Products Affected

neomail

  • neomail