CVE-2007-3796
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The password reset feature in the Spam Quarantine HTTP interface for MailMarshal SMTP 6.2.0.x before 6.2.1 allows remote attackers to modify arbitrary account information via a UserId variable with a large amount of trailing whitespace followed by a malicious value, which triggers SQL buffer truncation due to length inconsistencies between variables.
La característica de reinicio de la contraseña en el interface Spam Quarantine HTTP para SMTP 6.2.0.x anterior 6.2.1 permite a atacantes remotos modificar cuentas de información de su elección a través de un UserId variable con una gran cantidad de espacios en blanco seguidos por un valor malicioso, el cual dispara un truncamiento SQL de búfer debido a las inconsistencias de la longitud entre las variables.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-07-16 CVE Reserved
- 2007-07-17 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/2895 | Third Party Advisory | |
http://www.sec-1labs.co.uk/advisories/BTA_Full.pdf | Url Repurposed | |
http://www.securityfocus.com/bid/24936 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.grok.org.uk/pipermail/full-disclosure/2007-July/064676.html | 2024-02-14 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/26018 | 2024-02-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mailmarshal Search vendor "Mailmarshal" | Mailmarshal Smtp Search vendor "Mailmarshal" for product "Mailmarshal Smtp" | <= 6.2.0 Search vendor "Mailmarshal" for product "Mailmarshal Smtp" and version " <= 6.2.0" | - |
Affected
|