CVE-2006-0711

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/02/2006
Last modified:
03/04/2025

Description

The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:neomail:neomail:*:*:*:*:*:*:*:* 1.28 (including)