CVE-2006-4620
Estado: ModificadaMedia (4.6)—
The useredit_account.wdm module in Alt-N WebAdmin 3.2.5 running with MDaemon 9.0.6, and possibly earlier versions, allows remote authenticated domain administrators to gain privileges and obtain access to the system mail queue by modifying the mailbox of the MDaemon user account to use the mailbox of another account.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P
- Puntuación base: 4.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.21%
- Percentil entre todas las CVEs puntuadas: 68
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://files.altn.com/WebAdmin/Release/RelNotes_en.txt
- http://secunia.com/advisories/21727
- http://securityreason.com/securityalert/1516
- http://www.osvdb.org/28548
- http://www.securityfocus.com/archive/1/445153/100/0/threaded
- http://www.teklow.com/advisories/TTG0602.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28776
- http://files.altn.com/WebAdmin/Release/RelNotes_en.txt
- http://secunia.com/advisories/21727
- http://securityreason.com/securityalert/1516
- http://www.osvdb.org/28548
- http://www.securityfocus.com/archive/1/445153/100/0/threaded
- http://www.teklow.com/advisories/TTG0602.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28776
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-4620",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "HIGH",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-09-07T00:04:00.000",
"references": [
{
"url": "http://files.altn.com/WebAdmin/Release/RelNotes_en.txt",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/21727",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/1516",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/28548",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/445153/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.teklow.com/advisories/TTG0602.txt",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28776",
"source": "cve@mitre.org"
},
{
"url": "http://files.altn.com/WebAdmin/Release/RelNotes_en.txt",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/21727",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/1516",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/28548",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/445153/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.teklow.com/advisories/TTG0602.txt",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28776",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The useredit_account.wdm module in Alt-N WebAdmin 3.2.5 running with MDaemon 9.0.6, and possibly earlier versions, allows remote authenticated domain administrators to gain privileges and obtain access to the system mail queue by modifying the mailbox of the MDaemon user account to use the mailbox of another account."
},
{
"lang": "es",
"value": "El módulo useredit_account.wdm en Alt-N WebAdmin 3.2.5 que funciona con MDaemon 9.0.6, y posiblemente versiones anteriores, permite a un administrador de dominio remoto validado conseguir privilegios y obtener acceso a la cola del sistema de correo a través de la modificación de la bandeja de entrada de la cuenta de usuario de MDaemon para usar la bandeja de entrada de otra cuenta de usuario."
}
],
"lastModified": "2026-06-16T22:29:27.900",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:alt-n:webadmin:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D746906B-E5DF-4246-AAE9-AC7396E41848",
"versionEndIncluding": "3.2.5"
},
{
"criteria": "cpe:2.3:a:alt-n:webadmin:3.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC237046-3404-4D84-8008-0E15D1075B06"
},
{
"criteria": "cpe:2.3:a:alt-n:webadmin:3.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6F411993-6855-43FB-A090-210263CBD9F3"
},
{
"criteria": "cpe:2.3:a:alt-n:webadmin:3.2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "035509D1-3AA0-450C-8C0D-08A5DE381B2B"
},
{
"criteria": "cpe:2.3:a:alt-n:webadmin:3.2.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "841461CB-11A6-4672-A060-1AB6C8C62B3C"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org",
"evaluatorSolution": "Successful exploitation requires that the attacker is already a Domain administrator within the default domain of a MDaemon server.\r\nThis vulnerability is addressed in the following product release:\r\nAlt-N, WebAdmin, 3.2.6"
}