7.6

CVE-2007-3796

The password reset feature in the Spam Quarantine HTTP interface for MailMarshal SMTP 6.2.0.x before 6.2.1 allows remote attackers to modify arbitrary account information via a UserId variable with a large amount of trailing whitespace followed by a malicious value, which triggers SQL buffer truncation due to length inconsistencies between variables.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MailmarshalMailmarshal Smtp Version <= 6.2.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.89% 0.769
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.grok.org.uk/pipermail/full-disclosure/2007-July/064676.html
Patch
http://secunia.com/advisories/26018
Vendor Advisory
http://securityreason.com/securityalert/2895
http://www.sec-1labs.co.uk/advisories/BTA_Full.pdf
URL Repurposed
http://www.securityfocus.com/bid/24936