Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-1491

Опубликовано: 05 мая 2009
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, does not scan X- headers for malicious content, which allows remote attackers to bypass virus detection via a crafted message, as demonstrated by a message with an X-Testing header and no message body.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:mcafee:groupshield:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2000:*:*:*:*:*:*:*

EPSS

Процентиль: 48%
0.00247
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
почти 4 года назад

McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, does not scan X- headers for malicious content, which allows remote attackers to bypass virus detection via a crafted message, as demonstrated by a message with an X-Testing header and no message body.

EPSS

Процентиль: 48%
0.00247
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-20