CVE-2006-4954 describes a critical vulnerability in the updateuser servlet of Neon WebMail for Java versions prior to 5.08. The flaw stems from a lack of validation for the in_id parameter, enabling remote, unauthenticated attackers to manipulate arbitrary user information. This includes modifying passwords and permissions, viewing profile settings, and creating or deleting user accounts. With a CVSS score of 7.5 (High) and a FAUCET Risk Score of 92/100, this vulnerability presents a significant risk due to its low attack complexity and severe potential impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild or inclusion in CISA's KEV catalog, an exploit for this vulnerability is publicly available on ExploitDB. Despite its age and the availability of exploit code, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.06CPE matchmatch criteria | cpe:2.3:a:neosys:neon_webmail:5.06:*:java:*:*:*:*:* | ||
5.07CPE matchmatch criteria | cpe:2.3:a:neosys:neon_webmail:5.07:*:java:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.