6.4
CVE-2008-2784
- EPSS 1.36%
- Veröffentlicht 19.06.2008 20:41:00
- Zuletzt bearbeitet 16.06.2026 22:54:26
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The smtp_filter function in spamdyke before 3.1.8 does not filter RCPT commands after encountering the first DATA command, which allows remote attackers to use the server as an open mail relay by sending RCPT commands with invalid recipients, followed by a DATA command, followed by arbitrary RCPT commands and a second DATA command.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.36% | 0.681 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:P
|
http://secunia.com/advisories/30408
http://www.spamdyke.org/documentation/Changelog.txt
http://www.vupen.com/english/advisories/2008/1684/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/42658