Vulnerability CVE-2006-2917


Published: 2006-07-10   Modified: 2012-02-12

Description:
Directory traversal vulnerability in the IMAP server in WinGate 6.1.2.1094 and 6.1.3.1096, and possibly other versions before 6.1.4 Build 1099, allows remote authenticated users to read email of other users, or perform unauthorized operations on directories, via the (1) CREATE, (2) SELECT, (3) DELETE, (4) RENAME, (5) COPY, (6) APPEND, and (7) LIST commands.

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.5/10
4.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None
Affected software
QBIK -> Wingate 

 References:
http://secunia.com/advisories/20707
http://www.wingate.com/download.php
http://www.vupen.com/english/advisories/2006/2730
http://www.securityfocus.com/bid/18908
http://secunia.com/secunia_research/2006-48/advisory/

Copyright 2024, cxsecurity.com

 

Back to Top