Unrated severityNVD Advisory· Published Dec 23, 2006· Updated Apr 23, 2026
CVE-2006-6701
CVE-2006-6701
Description
Cross-site request forgery (CSRF) vulnerability in util.pl in @Mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers to modify arbitrary settings and perform unauthorized actions as an arbitrary user, as demonstrated using a settings action in the SRC attribute of an IMG element in an HTML e-mail.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- secunia.com/advisories/23472nvdVendor Advisory
- secunia.com/advisories/25328nvdVendor Advisory
- archives.neohapsis.com/archives/fulldisclosure/2007-01/0512.htmlnvd
- securitytracker.com/idnvd
- terra.calacode.com/mail/docs/changelog.htmlnvd
- www.netragard.com/html/recent_research.htmlnvd
- www.netragard.com/pdfs/research/ATMAIL-XSRF-ADVISORY-20061206.txtnvd
- www.securityfocus.com/archive/1/458109/100/100/threadednvd
- www.vupen.com/english/advisories/2007/1864nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/31259nvd
News mentions
0No linked articles in our index yet.