First published: Sat Feb 25 2006(Updated: )
NOCC Webmail 1.0 allows remote attackers to obtain the installation path via a direct request to html/header.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nCipher | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-0895 is classified as moderate due to the ability for remote attackers to obtain sensitive information.
To fix CVE-2006-0895, it is recommended to restrict access to the header.php file to authorized users only.
CVE-2006-0895 specifically affects installations of NOCC Webmail version 1.0.
CVE-2006-0895 facilitates information disclosure attacks by allowing attackers to determine the installation path.
No official patch is available for CVE-2006-0895, but implementing access controls can mitigate the risk.