CVE-2006-4371: Medium severity Alt-N WebAdmin vulnerability
Multiple directory traversal vulnerabilities in Alt-N WebAdmin 3.2.3 and 3.2.4 running with MDaemon 9.0.5, and possibly earlier, allow remote authenticated global administrators to read arbitrary files via a .. (dot dot) in the file parameter to (1) logfileview.wdm and (2) configfileview.wdm.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4371?
CVE-2006-4371 is considered to be a high severity vulnerability due to potential unauthorized access to sensitive files.
How do I fix CVE-2006-4371?
To address CVE-2006-4371, upgrade Alt-N WebAdmin to a version newer than 3.2.4 that includes patches for this vulnerability.
Who is affected by CVE-2006-4371?
CVE-2006-4371 affects users of Alt-N WebAdmin versions 3.2.3 and 3.2.4 running with MDaemon 9.0.5 or possibly earlier versions.
What exploit methods are used in CVE-2006-4371?
CVE-2006-4371 can be exploited by authenticated global administrators using directory traversal attacks through specific file parameters.
What types of files can be accessed due to CVE-2006-4371?
CVE-2006-4371 allows the reading of arbitrary files, including potentially sensitive log and configuration files.