Vulnerability Name: | CVE-2006-2917 (CCN-27646) | ||||||||
Assigned: | 2006-07-10 | ||||||||
Published: | 2006-07-10 | ||||||||
Updated: | 2011-03-08 | ||||||||
Summary: | Directory traversal vulnerability in the IMAP server in WinGate 6.1.2.1094 and 6.1.3.1096, and possibly other versions before 6.1.4 Build 1099, allows remote authenticated users to read email of other users, or perform unauthorized operations on directories, via the (1) CREATE, (2) SELECT, (3) DELETE, (4) RENAME, (5) COPY, (6) APPEND, and (7) LIST commands. | ||||||||
CVSS v3 Severity: | 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N) 4.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-2917 Source: CCN Type: SA20707 WinGate IMAP Commands Directory Traversal Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 20707 Source: MISC Type: Vendor Advisory http://secunia.com/secunia_research/2006-48/advisory/ Source: CCN Type: OSVDB ID: 27114 WinGate IMAP Multiple Command Traversal Arbitrary Mail Access Source: BID Type: UNKNOWN 18908 Source: CCN Type: BID-18908 Qbik WinGate IMAP Service Directory Traversal Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-2730 Source: CCN Type: WinGate Web site Download WinGate Source: MISC Type: UNKNOWN http://www.wingate.com/download.php Source: XF Type: UNKNOWN wingate-imap-directory-traversal(27646) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |