CVE-2006-0759
Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters in (4) calendar.event.php, (5) index.php, (6) pop.download.php, (7) read.bounce.php, (8) rules.block.php, (9) language.php, and (10) certain other scripts; and allow remote authenticated users to execute arbitrary SQL commands via (11) the folderid parameter in index.php and (12) possibly other parameters in certain other scripts, because $_SERVER['PHP_SELF'] is improperly handled.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.85% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- hivemail/hivemail
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2006-02/0162.htmlVendor Advisory
- http://forum.hivemail.com/showthread.php?p=26745
- http://secunia.com/advisories/18807
- http://securityreason.com/securityalert/422
- http://www.gulftech.org/?node=research&article_id=00098-02102006Vendor Advisory
- http://www.securityfocus.com/bid/16591
- http://www.vupen.com/english/advisories/2006/0527
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24623
- http://archives.neohapsis.com/archives/bugtraq/2006-02/0162.htmlVendor Advisory
- http://forum.hivemail.com/showthread.php?p=26745
- http://secunia.com/advisories/18807
- http://securityreason.com/securityalert/422
- http://www.gulftech.org/?node=research&article_id=00098-02102006Vendor Advisory
- http://www.securityfocus.com/bid/16591
- http://www.vupen.com/english/advisories/2006/0527
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24623
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.