CVE-2006-2917: Medium severity qbik wingate vulnerability
Directory traversal vulnerability in the IMAP server in WinGate 6.1.2.1094 and 6.1.3.1096, and possibly other versions before 6.1.4 Build 1099, allows remote authenticated users to read email of other users, or perform unauthorized operations on directories, via the (1) CREATE, (2) SELECT, (3) DELETE, (4) RENAME, (5) COPY, (6) APPEND, and (7) LIST commands.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2917?
CVE-2006-2917 is classified as a high severity vulnerability due to its potential for unauthorized access to sensitive email data.
How do I fix CVE-2006-2917?
To fix CVE-2006-2917, upgrade the WinGate software to version 6.1.4 Build 1099 or later.
What versions are affected by CVE-2006-2917?
CVE-2006-2917 affects WinGate versions 6.1.2.1094 and 6.1.3.1096.
What type of attack does CVE-2006-2917 enable?
CVE-2006-2917 enables authenticated remote users to exploit directory traversal and access the emails of other users.
Who is impacted by CVE-2006-2917?
Users of the WinGate IMAP server software versions 6.1.2.1094 and 6.1.3.1096 are impacted by CVE-2006-2917.