HIGH · 7.6

CVE-2006-4013

Multiple directory traversal vulnerabilities in Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allow remote attackers to read and ov...

Vulnerability Description

Multiple directory traversal vulnerabilities in Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allow remote attackers to read and overwrite certain files via directory traversal sequences in (1) DATABLOB-GET and (2) DATABLOB-SAVE requests.

CVSS Score

7.6

HIGH

AV:N/AC:H/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
SymantecBrightmail Antispam4.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2006-4013?

CVE-2006-4013 is a vulnerability with a CVSS score of 7.6 (HIGH). Multiple directory traversal vulnerabilities in Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allow remote attackers to read and ov...

How severe is CVE-2006-4013?

CVE-2006-4013 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-4013?

Check the references section above for vendor advisories and patch information. Affected products include: Symantec Brightmail Antispam.