PT-2004-2967 · Macallan · Macallan Mail Solution

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2071

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Macallan Mail Solution versions prior to 2.8.4.6
Description The issue allows remote attackers to bypass authentication in the web interface. This can be achieved via an HTTP GET request with two slashes ("//") after the server name.
Recommendations For versions prior to 2.8.4.6, update to a version that contains a fix for this issue to prevent authentication bypass in the web interface.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2071

Affected Products

Macallan Mail Solution