CVE-2008-6984
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname, or (2) a username that matches a valid password, as demonstrated using (a) SMTP and qmail, and (b) Courier IMAP and POP3.
Plesk v8.6.0, cunado la ordenación de nombres de login está activada, permite a atacantes remotos saltarse la autenticación y enviar correo electrónico spam a través de un mensaje con (1) un nombre de usuario codificado base64 que comienze con un shortname válido, o (2) un nombre de usuario que coincida con una contraseña válida, como se demostró utilizando (a) SMTP y qmail, y (b) Courier IMAP y POP3.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-08-17 CVE Reserved
- 2009-08-18 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.osvdb.org/51652 | Vdb Entry | |
http://www.securityfocus.com/bid/30956 | Vdb Entry | |
http://www.securitytracker.com/id?1020801 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44856 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/archive/1/495881 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Parallels Search vendor "Parallels" | Plesk Search vendor "Parallels" for product "Plesk" | 8.6.0 Search vendor "Parallels" for product "Plesk" and version "8.6.0" | linux\/unix |
Affected
| ||||||
Parallels Search vendor "Parallels" | Plesk Search vendor "Parallels" for product "Plesk" | 8.6.0 Search vendor "Parallels" for product "Plesk" and version "8.6.0" | windows |
Affected
|