First published: Sat Feb 25 2006(Updated: )
NOCC Webmail 1.0 stores e-mail attachments in temporary files with predictable filenames, which makes it easier for remote attackers to execute arbitrary code by accessing the e-mail attachment via directory traversal vulnerabilities.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nCipher | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0892 is rated as a moderate severity vulnerability due to its potential for remote code execution through predictable filenames.
To mitigate CVE-2006-0892, ensure that email attachments are stored with unique, non-predictable filenames and utilize proper access controls.
CVE-2006-0892 specifically affects version 1.0 of NOCC Webmail.
Yes, if exploited, CVE-2006-0892 can allow attackers to access sensitive email attachments leading to potential data leakage.
Attackers can exploit CVE-2006-0892 by utilizing directory traversal techniques to access predictable filenames of stored email attachments.