PT-2005-3112 · Phpxmail · Phpxmail
Steve
·
Published
2005-07-10
·
Updated
2016-10-18
·
CVE-2005-2183
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
PhpXmail versions 0.7 through 1.1
Description:
The issue concerns the handling of large passwords in the class.xmail.php file, which can prevent an error message from being returned. This allows remote attackers to bypass authentication and gain unauthorized access.
Recommendations:
For PhpXmail versions 0.7 through 1.1, consider restricting access to the authentication mechanism until a fix is available. As a temporary workaround, limit the password length to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpxmail