The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, which triggers an LDAP anonymous bind.
References
Configurations
History
21 Nov 2024, 01:59
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/124054 - Exploit | |
References | () http://www.exploit-db.com/exploits/29706 - Exploit | |
References | () http://www.osvdb.org/100007 - | |
References | () http://www.securityfocus.com/bid/63793 - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/89077 - |
Information
Published : 2014-10-26 20:55
Updated : 2024-11-21 01:59
NVD link : CVE-2013-6796
Mitre link : CVE-2013-6796
CVE.ORG link : CVE-2013-6796
JSON object : View
Products Affected
deeproot_linux
- deepofix
CWE
CWE-264
Permissions, Privileges, and Access Controls