PT-2004-2967 · Macallan · Macallan Mail Solution
Publicado
2004-12-31
·
Atualizado
2017-07-11
·
CVE-2004-2071
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Macallan Mail Solution versions prior to 2.8.4.6
Description
The issue allows remote attackers to bypass authentication in the web interface. This can be achieved via an HTTP GET request with two slashes ("//") after the server name.
Recommendations
For versions prior to 2.8.4.6, update to a version that contains a fix for this issue to prevent authentication bypass in the web interface.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Macallan Mail Solution