Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-3275

Опубликовано: 19 июн. 2007
Источник: nvd
CVSS2: 7.1
EPSS Низкий

Описание

MailWasher Server before 2.2.1, when used with LDAP or Active Directory (AD), does not properly handle blank passwords, which allows remote attackers to access an arbitrary user account and read the spam e-mail messages stored for that account, possibly related to the LoginCheck::doPost function in mwi/servlet/Login.cpp. NOTE: some of these details are obtained from third party information.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mailwasher:mailwasher_server:*:*:*:*:*:*:*:*
Версия до 2.2.0 (включая)

EPSS

Процентиль: 70%
0.00638
Низкий

7.1 High

CVSS2

Дефекты

CWE-255

Связанные уязвимости

github
почти 4 года назад

MailWasher Server before 2.2.1, when used with LDAP or Active Directory (AD), does not properly handle blank passwords, which allows remote attackers to access an arbitrary user account and read the spam e-mail messages stored for that account, possibly related to the LoginCheck::doPost function in mwi/servlet/Login.cpp. NOTE: some of these details are obtained from third party information.

EPSS

Процентиль: 70%
0.00638
Низкий

7.1 High

CVSS2

Дефекты

CWE-255