Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-1218

Опубликовано: 10 мар. 2008
Источник: nvd
CVSS2: 6.8
EPSS Средний

Описание

Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*
Версия до 1.0.12 (включая)
cpe:2.3:a:dovecot:dovecot:*:rc2:*:*:*:*:*:*
Версия до 1.1 (включая)

EPSS

Процентиль: 95%
0.18733
Средний

6.8 Medium

CVSS2

Дефекты

CWE-255

Связанные уязвимости

ubuntu
больше 17 лет назад

Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified.

redhat
больше 17 лет назад

Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified.

debian
больше 17 лет назад

Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1 ...

github
больше 3 лет назад

Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified.

EPSS

Процентиль: 95%
0.18733
Средний

6.8 Medium

CVSS2

Дефекты

CWE-255