PT-2002-3120 · Gordano · Gordano Messaging Server (Gms) Mail

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-2408

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Gordano Messaging Server (GMS) Mail 8
Description The issue allows remote attackers to bypass JUCE filters by sending an email message to more than one user on the GMS server, as the server only filters email messages for the first recipient.
Recommendations For Gordano Messaging Server (GMS) Mail 8, consider implementing a workaround to filter email messages for all recipients, not just the first one, until a proper fix is available. As a temporary mitigation measure, restrict the ability to send emails to multiple users simultaneously to minimize the risk of filter bypass.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-2408

Affected Products

Gordano Messaging Server (Gms) Mail