CVE Vulnerabilities

CVE-2006-4954

Published: Sep 23, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile settings, and (4) creating and (5) deleting users.

Affected Software

NameVendorStart VersionEnd Version
Neon_webmailNeosys5.06 (including)5.06 (including)
Neon_webmailNeosys5.07 (including)5.07 (including)

References