PT-2002-3120 · Gordano · Gordano Messaging Server (Gms) Mail
Publicado
2002-12-31
·
Atualizado
2008-09-05
·
CVE-2002-2408
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Gordano Messaging Server (GMS) Mail 8
Description
The issue allows remote attackers to bypass JUCE filters by sending an email message to more than one user on the GMS server, as the server only filters email messages for the first recipient.
Recommendations
For Gordano Messaging Server (GMS) Mail 8, consider implementing a workaround to filter email messages for all recipients, not just the first one, until a proper fix is available. As a temporary mitigation measure, restrict the ability to send emails to multiple users simultaneously to minimize the risk of filter bypass.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Gordano Messaging Server (Gms) Mail