The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile settings, and (4) creating and (5) deleting users.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/20109 | patch vdb entry exploit |
http://vuln.sg/neonmail506-en.html | patch exploit |
http://secunia.com/advisories/22029 | patch vendor advisory third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/29089 | vdb entry |
http://www.securityfocus.com/bid/84203 | vdb entry |