Vulnerability Name: | CVE-2006-4013 (CCN-28058) | ||||||||
Assigned: | 2006-07-27 | ||||||||
Published: | 2006-07-27 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | Multiple directory traversal vulnerabilities in Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allow remote attackers to read and overwrite certain files via directory traversal sequences in (1) DATABLOB-GET and (2) DATABLOB-SAVE requests. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.6 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C) 6.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
6.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-22 | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-4013 Source: CCN Type: Symantec Brightmail AntiSpam Web page Symantec Brightmail AntiSpam Source: CCN Type: SA21223 Symantec Brightmail AntiSpam Multiple Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 21223 Source: CCN Type: Symantec Security Response SYM06-012 Symantec Brightmail AntiSpam Multiple Vulnerabilities Source: CONFIRM Type: Patch, Vendor Advisory http://securityresponse.symantec.com/avcenter/security/Content/2006.07.27.html Source: CCN Type: SECTRACK ID: 1016600 Symantec Brightmail AntiSpam Lets Remote Users Traverse the Directory Source: SECTRACK Type: Patch 1016600 Source: OSVDB Type: UNKNOWN 27589 Source: OSVDB Type: UNKNOWN 27590 Source: CCN Type: OSVDB ID: 27589 Symantec Brightmail AntiSpam bmagnet Service Crafted Request Component State Manipulation Source: CCN Type: OSVDB ID: 27590 Symantec Brightmail AntiSpam DATABLOB-* Request Traversal Arbitrary File Write Source: BID Type: UNKNOWN 19182 Source: CCN Type: BID-19182 Symantec Brightmail AntiSpam Control Center Multiple Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2006-3018 Source: XF Type: UNKNOWN brightmail-datablob-directory-traversal(28058) Source: XF Type: UNKNOWN brightmail-datablob-directory-traversal(28058) Source: XF Type: UNKNOWN brightmail-post-dos(28059) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |