Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown
CVE-2007-0496
Disclosure Date: January 25, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the g_strRootDir parameter.
0
Attacker Value
Unknown
CVE-2007-0157
Disclosure Date: January 09, 2007 (last updated October 04, 2023)
Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index.
0
Attacker Value
Unknown
CVE-2006-4953
Disclosure Date: September 23, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary SQL commands via the (1) adr_sortkey and (2) adr_sortkey_desc parameters in the (a) addrlist servlet, and the (3) sortkey and (4) sortkey_desc parameters in the (b) maillist servlet.
0
Attacker Value
Unknown
CVE-2006-4952
Disclosure Date: September 23, 2006 (last updated October 04, 2023)
The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail folders, specified by the folderid and tofolderid parameters, via the ID parameter.
0
Attacker Value
Unknown
CVE-2006-4956
Disclosure Date: September 23, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote attackers to inject arbitrary web script or HTML via the in_name parameter, as used by the Name field.
0
Attacker Value
Unknown
CVE-2006-4951
Disclosure Date: September 23, 2006 (last updated October 04, 2023)
Neon WebMail for Java before 5.08 allows remote attackers to execute arbitrary Java (JSP) code by sending an e-mail message with a JSP file attachment, which is stored under the web root with a predictable filename.
0
Attacker Value
Unknown
CVE-2006-4955
Disclosure Date: September 23, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the (1) savefolder and (2) savefilename parameters.
0
Attacker Value
Unknown
CVE-2006-4954
Disclosure Date: September 23, 2006 (last updated October 04, 2023)
The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile settings, and (4) creating and (5) deleting users.
0
Attacker Value
Unknown
CVE-2006-1941
Disclosure Date: April 20, 2006 (last updated October 04, 2023)
Neon Responder 5.4 for LANsurveyor allows remote attackers to cause a denial of service (application outage) via a crafted Clock Synchronisation packet that triggers an access violation.
0
Attacker Value
Unknown
CVE-2004-0398
Disclosure Date: July 07, 2004 (last updated February 22, 2025)
Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.
0