PT-2004-2967 · Macallan · Macallan Mail Solution
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2071
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Macallan Mail Solution versions prior to 2.8.4.6
Description
The issue allows remote attackers to bypass authentication in the web interface. This can be achieved via an HTTP GET request with two slashes ("//") after the server name.
Recommendations
For versions prior to 2.8.4.6, update to a version that contains a fix for this issue to prevent authentication bypass in the web interface.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macallan Mail Solution