CVE-2007-3275

MailWasher Server before 2.2.1, when used with LDAP or Active Directory (AD), does not properly handle blank passwords, which allows remote attackers to access an arbitrary user account and read the spam e-mail messages stored for that account, possibly related to the LoginCheck::doPost function in mwi/servlet/Login.cpp. NOTE: some of these details are obtained from third party information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mailwasher:mailwasher_server:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:32

Type Values Removed Values Added
References () http://osvdb.org/37538 - () http://osvdb.org/37538 -
References () http://secunia.com/advisories/25695 - Patch, Vendor Advisory () http://secunia.com/advisories/25695 - Patch, Vendor Advisory
References () http://sourceforge.net/project/shownotes.php?release_id=515127 - () http://sourceforge.net/project/shownotes.php?release_id=515127 -
References () http://www.securityfocus.com/bid/24507 - () http://www.securityfocus.com/bid/24507 -
References () http://www.vupen.com/english/advisories/2007/2239 - Vendor Advisory () http://www.vupen.com/english/advisories/2007/2239 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/34925 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/34925 -

Information

Published : 2007-06-19 21:30

Updated : 2024-11-21 00:32


NVD link : CVE-2007-3275

Mitre link : CVE-2007-3275

CVE.ORG link : CVE-2007-3275


JSON object : View

Products Affected

mailwasher

  • mailwasher_server
CWE
CWE-255

Credentials Management Errors