PT-2005-3112 · Phpxmail · Phpxmail

Steve

·

Publicado

2005-07-10

·

Atualizado

2016-10-18

·

CVE-2005-2183

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: PhpXmail versions 0.7 through 1.1
Description: The issue concerns the handling of large passwords in the class.xmail.php file, which can prevent an error message from being returned. This allows remote attackers to bypass authentication and gain unauthorized access.
Recommendations: For PhpXmail versions 0.7 through 1.1, consider restricting access to the authentication mechanism until a fix is available. As a temporary workaround, limit the password length to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2183

Produtos afetados

Phpxmail