CVE-2007-3796
Last modified
CVE-2007-3796 is a vulnerability of currently unknown severity. The password reset feature in the Spam Quarantine HTTP interface for MailMarshal SMTP 6.2.0.x before 6.2.1 allows remote attackers to modify arbitrary account information via a UserId variable with a large amount of trailing whitespace followed by a malicious value, which triggers SQL buffer truncation due to length inconsistencies between variables.. EPSS estimates a 1.89% chance of exploitation in the next 30 days.
Description
The password reset feature in the Spam Quarantine HTTP interface for MailMarshal SMTP 6.2.0.x before 6.2.1 allows remote attackers to modify arbitrary account information via a UserId variable with a large amount of trailing whitespace followed by a malicious value, which triggers SQL buffer truncation due to length inconsistencies between variables.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mailmarshal | Mailmarshal Smtp | <= 6.2.0 |
References
- http://secunia.com/advisories/26018Vendor Advisory
- http://www.sec-1labs.co.uk/advisories/BTA_Full.pdfURL Repurposed
- http://secunia.com/advisories/26018Vendor Advisory
- http://www.sec-1labs.co.uk/advisories/BTA_Full.pdfURL Repurposed
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-3796?
How severe is CVE-2007-3796?
How do I fix CVE-2007-3796?
Are you affected by CVE-2007-3796?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
