Neosys maintains a narrowly scoped product line centered on Neon Webmail, a web-based email application that represents a focused but strategically important communications platform. The vendor's disclosed vulnerabilities frequently acquire public exploit code, underscoring the appeal of email systems as attack targets and the importance of timely patching for this product. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Neosys over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4952HIGH The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail folders, specified by the fold | Sep 23, 2006 | 7.5 | 31 | NO | YES |
CVE-2006-4954HIGH The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demons | Sep 23, 2006 | 7.5 | 31 | NO | YES |
CVE-2006-4953HIGH Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary SQL commands via the (1) adr_sortkey and (2) adr_sortkey_des | Sep 23, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-4956MEDIUM Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote attackers to inject arbitrary web script or HTML via the in_na | Sep 23, 2006 | 6.8 | 28 | NO | YES |
CVE-2006-4955MEDIUM Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in th | Sep 23, 2006 | 5.0 | 25 | NO | YES |
CVE-2006-4951HIGH Neon WebMail for Java before 5.08 allows remote attackers to execute arbitrary Java (JSP) code by sending an e-mail message with a JSP file attachment, which is stored under the we | Sep 23, 2006 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Neosys.
Media articles that mention a CVE ID that affects a product developed by Neosys — matched by CVE ID, not by vendor name.