CVE-2007-6714
Last modified
CVE-2007-6714 is a vulnerability of currently unknown severity. DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which causes the LDAP bind to indicate success based on anonymous authentication.. EPSS estimates a 2.39% chance of exploitation in the next 30 days.
Description
DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which causes the LDAP bind to indicate success based on anonymous authentication.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dbmail | Dbmail | 2.2.6 |
| Dbmail | Dbmail | 2.2.7 |
| Dbmail | Dbmail | 2.2.8 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-6714?
How severe is CVE-2007-6714?
How do I fix CVE-2007-6714?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-6707Multiple cross-site scripting (XSS) vulnerabilities on the C…
- CVE-2007-6708Multiple cross-site request forgery (CSRF) vulnerabilities o…
- CVE-2007-6709The Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.…
- CVE-2007-6711Unspecified vulnerability in customer.php in FreeWebshop.org…
- CVE-2007-6712Integer overflow in the hrtimer_forward function (hrtimer.c)…
- CVE-2007-6713Unspecified vulnerability in Flip4Mac WMV before 2.2.0.49 ha…
- CVE-2007-6715Mozilla Firefox allows remote attackers to cause a denial of…
- CVE-2007-6716fs/direct-io.c in the dio subsystem in the Linux kernel befo…5.5
- CVE-2007-6717Buffer overflow in tftp in bos.net.tcp.client in IBM AIX 5.2…
- CVE-2007-6718MPlayer, possibly 1.0rc1, allows remote attackers to cause a…
- CVE-2007-6719SQL injection vulnerability in Wiz-Ad 1.3 allows remote atta…
- CVE-2007-6720libmikmod 3.1.9 through 3.2.0, as used by MikMod, SDL-mixer,…
Are you affected by CVE-2007-6714?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
