CVE-2006-7062: High severity kmail kmail vulnerability
Published Feb 24, 2007
·Updated
calendar.php in Kamgaing Email System (kmail) 2.3 and earlier allows remote attackers to obtain the full path of the server via an invalid d parameter, which leaks the path in an error message.
Affected Software
1 affected component
kmail KMail<=2.3
Event History
Feb 24, 2007
CVE Published
01:28 AM
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-7062?
CVE-2006-7062 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2006-7062?
To fix CVE-2006-7062, upgrade to a version of Kmail later than 2.3 to prevent path disclosure.
3
What is the impact of CVE-2006-7062?
The impact of CVE-2006-7062 is that it allows remote attackers to gain knowledge of the server's file path through an error message.
4
Which versions of Kmail are affected by CVE-2006-7062?
CVE-2006-7062 affects Kmail versions 2.3 and earlier.
5
Can CVE-2006-7062 be exploited remotely?
Yes, CVE-2006-7062 can be exploited remotely by attackers using an invalid parameter to trigger the error message.