Lucene search

K
cveMitreCVE-2006-2824
HistoryJun 05, 2006 - 5:02 p.m.

CVE-2006-2824

2006-06-0517:02:00
mitre
web.nvd.nist.gov
36
cve-2006-2824
logicalware mailmanager
remote attack
data modification
administrative access
postgresql
vulnerability

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0.012

Percentile

85.2%

Logicalware MailManager before 2.0.10 does not remove 0xc8 0x27 (0xc8 followed by a single-quote character) from the data stream to the server, which allows remote attackers to modify data and gain administrative access when PostgreSQL is used, aka “bug #1494281 - Postgres encoding security hole.” NOTE: while this issue involves PostgreSQL, it is specific to MailManager’s interface to PostgreSQL and is therefore a different vulnerability than CVE-2006-2313 and CVE-2006-2314.

Affected configurations

Nvd
Node
logicalwaremailmanagerMatch2.0
OR
logicalwaremailmanagerMatch2.0.1
OR
logicalwaremailmanagerMatch2.0.1_rc2
OR
logicalwaremailmanagerMatch2.0.2
OR
logicalwaremailmanagerMatch2.0.3
OR
logicalwaremailmanagerMatch2.0.4
OR
logicalwaremailmanagerMatch2.0.5
OR
logicalwaremailmanagerMatch2.0.6
OR
logicalwaremailmanagerMatch2.0.7
OR
logicalwaremailmanagerMatch2.0.8
OR
logicalwaremailmanagerMatch2.0.9
OR
logicalwaremailmanagerMatch2.0_r7
VendorProductVersionCPE
logicalwaremailmanager2.0cpe:2.3:a:logicalware:mailmanager:2.0:*:*:*:*:*:*:*
logicalwaremailmanager2.0.1cpe:2.3:a:logicalware:mailmanager:2.0.1:*:*:*:*:*:*:*
logicalwaremailmanager2.0.1_rc2cpe:2.3:a:logicalware:mailmanager:2.0.1_rc2:*:*:*:*:*:*:*
logicalwaremailmanager2.0.2cpe:2.3:a:logicalware:mailmanager:2.0.2:*:*:*:*:*:*:*
logicalwaremailmanager2.0.3cpe:2.3:a:logicalware:mailmanager:2.0.3:*:*:*:*:*:*:*
logicalwaremailmanager2.0.4cpe:2.3:a:logicalware:mailmanager:2.0.4:*:*:*:*:*:*:*
logicalwaremailmanager2.0.5cpe:2.3:a:logicalware:mailmanager:2.0.5:*:*:*:*:*:*:*
logicalwaremailmanager2.0.6cpe:2.3:a:logicalware:mailmanager:2.0.6:*:*:*:*:*:*:*
logicalwaremailmanager2.0.7cpe:2.3:a:logicalware:mailmanager:2.0.7:*:*:*:*:*:*:*
logicalwaremailmanager2.0.8cpe:2.3:a:logicalware:mailmanager:2.0.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0.012

Percentile

85.2%