PT-2005-3112 · Phpxmail · Phpxmail
Steve
·
Publicado
2005-07-10
·
Atualizado
2016-10-18
·
CVE-2005-2183
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
PhpXmail versions 0.7 through 1.1
Description:
The issue concerns the handling of large passwords in the class.xmail.php file, which can prevent an error message from being returned. This allows remote attackers to bypass authentication and gain unauthorized access.
Recommendations:
For PhpXmail versions 0.7 through 1.1, consider restricting access to the authentication mechanism until a fix is available. As a temporary workaround, limit the password length to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Phpxmail