CVE-2006-6964: Medium severity MailEnable MailEnable Professional vulnerability
MailEnable Professional before 1.78 provides a cleartext user password when an administrator edits the user's settings, which allows remote authenticated administrators to obtain sensitive information by viewing the HTML source.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6964?
CVE-2006-6964 is considered a medium severity vulnerability due to the exposure of cleartext user passwords.
How do I fix CVE-2006-6964?
To address CVE-2006-6964, upgrade to MailEnable Professional version 1.78 or later.
What does CVE-2006-6964 allow an attacker to do?
CVE-2006-6964 allows authenticated administrators to view sensitive user passwords by inspecting the HTML source when editing user settings.
Which versions of MailEnable Professional are affected by CVE-2006-6964?
MailEnable Professional versions 1.7, 1.71, 1.72, 1.73, 1.74, 1.75, 1.76, and 1.77 are all affected by CVE-2006-6964.
Is there a workaround for CVE-2006-6964 while I cannot update?
There is no known workaround for CVE-2006-6964; the only resolution is to upgrade to a fixed version.