← Vulnerability feed

Vulnerability record · CVE-2006-2308 · published 2 June 2006

CVE-2006-2308: Etype eserv vulnerability

Etype · Eserv

Directory traversal vulnerability in the IMAP service in EServ/3 3.25 allows remote authenticated users to read other user's email messages, create/rename arbitrary directories on the system, and delete empty directories via directory traversal sequences in the (1) CREATE, (2) SELECT, (3) DELETE, (4) RENAME, (5) COPY or (6) APPEND commands.

5.5 CVSS 2.0 Medium EPSS 1.6% · top 24.5%
5.5CVSS 2.0 base score
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in the IMAP service in EServ/3 3.25 allows remote authenticated users to read other user's email messages, create/rename arbitrary directories on the system, and delete empty directories via directory traversal sequences in the (1) CREATE, (2) SELECT, (3) DELETE, (4) RENAME, (5) COPY or (6) APPEND commands.

AV:N/AC:L/Au:S/C:P/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-2308 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-4588Etype eserv memory buffer overflow vulnerabilityStack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a denial of service (daemon crash) …EPSS 6.8%10.0CVE-2000-0523Etype eserv vulnerabilityBuffer overflow in the logging feature of EServ 2.9.2 and earlier allows an attacker to execute arbitrary commands via a long MKD command.EPSS 5.0%7.5CVE-2002-0222Etype eserv vulnerabilityEtype Eserv 2.97 allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command.EPSS 1.6%7.5CVE-2000-0907Etype eserv vulnerabilityEServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM comman…EPSS 2.0%5.0CVE-2003-1266Etype eserv vulnerabilityThe (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of se…EPSS 3.9%5.0CVE-2003-0290Etype eserv vulnerabilityMemory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is…EPSS 7.8%5.0CVE-2002-0221Etype eserv vulnerabilityEtype Eserv 2.97 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of PASV commands that consume ports 10…EPSS 1.6%5.0CVE-2002-0112Etype eserv vulnerabilityEtype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL.EPSS 8.1%

Source: NIST National Vulnerability Database (record CVE-2006-2308), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.