CVE-2006-0611: High severity Atmail atmail vulnerability
Published Feb 9, 2006
·Updated
Directory traversal vulnerability in compose.pl in @Mail 4.3 and earlier for Windows allows remote attackers to upload arbitrary files to arbitrary locations via a .. (dot dot) in the unique parameter.
Affected Software
1 affected component
Atmail atmail=4.3
Remediation
Patch Available
Patch Available
Event History
Feb 9, 2006
CVE Published
12:02 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0611?
CVE-2006-0611 has a medium severity rating due to its potential for file upload vulnerabilities.
2
How do I fix CVE-2006-0611?
To fix CVE-2006-0611, upgrade to a version of @Mail later than 4.3 that has patched the directory traversal vulnerability.
3
What are the risks associated with CVE-2006-0611?
The risks associated with CVE-2006-0611 include unauthorized file uploads which could lead to remote code execution or data breaches.
4
Which software is affected by CVE-2006-0611?
CVE-2006-0611 specifically affects @Mail version 4.3 and earlier for Windows.
5
Who can exploit CVE-2006-0611?
Remote attackers can exploit CVE-2006-0611 by manipulating the unique parameter to perform directory traversal.