VulnerabilityModified
CVE-2006-3566
search.results.php in HiveMail 3.1 and earlier allows remote attackers to obtain the installation path via certain manipulations related to the (1) searchdate and (2) folderids parameters.
MEDIUM 5.0EPSS 1.39%
Does this matter?
Lower severity and a low EPSS score (1.39%). Track it; it rarely justifies an emergency change on its own.
Description
search.results.php in HiveMail 3.1 and earlier allows remote attackers to obtain the installation path via certain manipulations related to the (1) searchdate and (2) folderids parameters.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.39% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- hivemail/hivemail
- Source
- cve@mitre.org
References
- http://pridels0.blogspot.com/2006/07/hivemail-vuln.html
- http://securitytracker.com/id?1016531
- http://www.osvdb.org/27104
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27696
- http://pridels0.blogspot.com/2006/07/hivemail-vuln.html
- http://securitytracker.com/id?1016531
- http://www.osvdb.org/27104
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27696
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.