Логотип exploitDog
bind:CVE-2006-4954
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2006-4954

Количество 2

Количество 2

nvd логотип

CVE-2006-4954

больше 19 лет назад

The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile settings, and (4) creating and (5) deleting users.

CVSS2: 7.5
EPSS: Низкий
github логотип

GHSA-6mc6-x498-8q9c

почти 4 года назад

The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile settings, and (4) creating and (5) deleting users.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2006-4954

The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile settings, and (4) creating and (5) deleting users.

CVSS2: 7.5
8%
Низкий
больше 19 лет назад
github логотип
GHSA-6mc6-x498-8q9c

The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile settings, and (4) creating and (5) deleting users.

8%
Низкий
почти 4 года назад

Уязвимостей на страницу