Unrated severityNVD Advisory· Published Feb 18, 2006· Updated Apr 16, 2026
CVE-2006-0757
CVE-2006-0757
Description
Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters in (4) calendar.event.php, (5) index.php, (6) pop.download.php, (7) read.bounce.php, (8) rules.block.php, (9) language.php, and (10) certain other scripts, as demonstrated by an addressbook.update.php request with a contactgroupid value of phpinfo() preceded by facilitators.
Affected products
10cpe:2.3:a:hivemail:hivemail:1.1:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:hivemail:hivemail:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:hivemail:hivemail:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:hivemail:hivemail:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:hivemail:hivemail:1.2.1_beta1:*:*:*:*:*:*:*
- cpe:2.3:a:hivemail:hivemail:1.2.1_rc:*:*:*:*:*:*:*
- cpe:2.3:a:hivemail:hivemail:1.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:hivemail:hivemail:1.2_sp1:*:*:*:*:*:*:*
- cpe:2.3:a:hivemail:hivemail:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:hivemail:hivemail:1.3_beta1:*:*:*:*:*:*:*
- cpe:2.3:a:hivemail:hivemail:1.3_rc1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- archives.neohapsis.com/archives/bugtraq/2006-02/0162.htmlnvdVendor Advisory
- www.gulftech.orgnvdVendor Advisory
- forum.hivemail.com/showthread.phpnvd
- secunia.com/advisories/18807nvd
- www.securityfocus.com/bid/16591nvd
- www.vupen.com/english/advisories/2006/0527nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/24618nvd
News mentions
0No linked articles in our index yet.