Back to Database
Status published
Medium
CVE-2006-0127
Directory traversal vulnerability in the IMAP service of Rockliffe MailSite...
Vulnerability Description
Directory traversal vulnerability in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote authenticated users to rename the folders of other users via a .. (dot dot) in the RENAME command.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-0127
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html
- http://www.osvdb.org/22229
- http://www.vupen.com/english/advisories/2006/0055
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041039.html
- http://secunia.com/advisories/18318
- http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt
More from rockliffe
View All →CVE-2006-0790
Rockliffe MailSite 7.0 and earlier allows remote attackers to cause...
Medium
5
CVE-2006-0342
RockLiffe MailSite HTTP Mail management agent (httpma) 7.0.3.1 allows remote...
High
7.8
CVE-2006-0341
Cross-site scripting (XSS) vulnerability in WCONSOLE.DLL in Rockliffe MailSite 5.x...
Medium
4.3
CVE-2006-0130
Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe...
High
7.5
CVE-2006-0129
Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe...
Medium
5
Affected Vendor
rockliffe
View all reports →Affected Software
mailsite
Vulnerable Versions:
0
Timeline
Official Publish:
January 9th, 2006
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.