First published: Thu Sep 07 2006(Updated: )
The useredit_account.wdm module in Alt-N WebAdmin 3.2.5 running with MDaemon 9.0.6, and possibly earlier versions, allows remote authenticated domain administrators to gain privileges and obtain access to the system mail queue by modifying the mailbox of the MDaemon user account to use the mailbox of another account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alt-N WebAdmin | =3.2.4 | |
Alt-N WebAdmin | =3.0.2 | |
Alt-N WebAdmin | <=3.2.5 | |
Alt-N WebAdmin | =3.2.3 | |
Alt-N WebAdmin | =3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4620 has a medium severity rating due to the potential for privilege escalation for remote authenticated domain administrators.
To fix CVE-2006-4620, update Alt-N WebAdmin to version 3.2.6 or later to mitigate the vulnerability.
CVE-2006-4620 affects Alt-N WebAdmin versions up to and including 3.2.5, as well as earlier versions such as 3.0.2, 3.0.3, and 3.2.3.
Remote authenticated domain administrators using affected versions of Alt-N WebAdmin are at risk with CVE-2006-4620.
CVE-2006-4620 can allow unauthorized access to the system mail queue, compromising mail integrity and security.