CVE Vulnerabilities

CVE-2006-2308

Published: Jun 02, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in the IMAP service in EServ/3 3.25 allows remote authenticated users to read other users email messages, create/rename arbitrary directories on the system, and delete empty directories via directory traversal sequences in the (1) CREATE, (2) SELECT, (3) DELETE, (4) RENAME, (5) COPY or (6) APPEND commands.

Affected Software

Name Vendor Start Version End Version
Eserv Etype 3.0 (including) 3.0 (including)
Eserv Etype 3.25 (including) 3.25 (including)

References