Marshal MailMarshal SMTP Spam Quarantine Interface User Password Change Vulnerability
BID:24936
Info
Marshal MailMarshal SMTP Spam Quarantine Interface User Password Change Vulnerability
| Bugtraq ID: | 24936 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3796 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2007 12:00AM |
| Updated: | Jul 17 2007 08:56PM |
| Credit: | Gary O'leary-Steele is credited with the discovery of this vulnerability. |
| Vulnerable: |
Marshal MailMarshal SMTP 6.2 |
| Not Vulnerable: |
Marshal MailMarshal SMTP 6.2.1 |
Discussion
Marshal MailMarshal SMTP Spam Quarantine Interface User Password Change Vulnerability
Marshal MailMarshal SMTP is prone to a vulnerability that may permit attackers to change arbitrary passwords.
Exploiting this issue may allow an attacker to change an arbitrary user's password, bypass the authentication mechanism, and gain unauthorized access to the affected application. This may lead to other attacks.
Versions prior to MailMarshal SMTP6.2.1 are vulnerable.
Marshal MailMarshal SMTP is prone to a vulnerability that may permit attackers to change arbitrary passwords.
Exploiting this issue may allow an attacker to change an arbitrary user's password, bypass the authentication mechanism, and gain unauthorized access to the affected application. This may lead to other attacks.
Versions prior to MailMarshal SMTP6.2.1 are vulnerable.
Exploit / POC
Marshal MailMarshal SMTP Spam Quarantine Interface User Password Change Vulnerability
An attacker can exploit this issue via a browser. Note that the attacker requires prior knowledge of a victim's email address registered with the application.
An attacker can exploit this issue via a browser. Note that the attacker requires prior knowledge of a victim's email address registered with the application.
Solution / Fix
Marshal MailMarshal SMTP Spam Quarantine Interface User Password Change Vulnerability
Solution:
The vendor has released MailMarshal SMTP 6.2.1 to address this issue; please contact the vendor for information on obtaining and installing fixes.
Solution:
The vendor has released MailMarshal SMTP 6.2.1 to address this issue; please contact the vendor for information on obtaining and installing fixes.
References
Marshal MailMarshal SMTP Spam Quarantine Interface User Password Change Vulnerability
References:
References:
- Buffer Truncation in Microsoft SQL Server Based Applications 1.1 (Sec-1 Ltd)
- MailMarshal Web Site (MailMarshal)