CVE-2006-6701: CSRF
Cross-site request forgery (CSRF) vulnerability in util.pl in @Mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers to modify arbitrary settings and perform unauthorized actions as an arbitrary user, as demonstrated using a settings action in the SRC attribute of an IMG element in an HTML e-mail.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6701?
CVE-2006-6701 is considered a medium severity vulnerability due to its ability to allow unauthorized actions by remote attackers.
How do I fix CVE-2006-6701?
To fix CVE-2006-6701, upgrade to the latest version of Atmail WebMail that addresses the CSRF vulnerability.
What types of software are affected by CVE-2006-6701?
CVE-2006-6701 affects Atmail WebMail versions 3.0, 4.0, and 4.51.
What can an attacker do with CVE-2006-6701?
An attacker exploiting CVE-2006-6701 can modify settings and perform unauthorized actions as any user within the affected application.
Is CVE-2006-6701 easy to exploit?
CVE-2006-6701 can be easily exploited using CSRF attack techniques, such as embedding malicious URLs.