Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6714 (dbmail)

BugsAlert Home > CVE-2007-6714 (dbmail)
 
 

DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which causes the LDAP bind to indicate success based on anonymous authentication.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6714

Learn more about CVE-2007-6714 (dbmail)
 
Tags: cve-2007-6714 dbmail

Related Items

      VBS_SOLOW.AK

      FrSIRT - Ubuntu Security Update Fixes Kernel Security Bypass and DoS Issues

      Joomla Weak Random Password Reset Token Vulnerability

      CVE-2008-0485 (MPlayer)

      Ubuntu Security Update Fixes Kernel Security Bypass and DoS Issues

      PatchLink Update Client for Unix Insecure Temporary Files

      Bugtraq: iDefense Security Advisory 07.08.08: Microsoft SQL Server Restore Integer Underflow Vulnerability

 

Pixel