CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.0. It may be remotely exploitable.
CVE
CVE-2006-0711
Severity
MEDIUM
CVSS
5
EPSS
1.49%
Original NVD Description
The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled.