CVE-2007-3796 Information
Feb 14, 2021
cve
Description
The password reset feature in the Spam Quarantine HTTP interface for MailMarshal SMTP 6.2.0.x before 6.2.1 allows remote attackers to modify arbitrary account information via a UserId variable with a large amount of trailing whitespace followed by a malicious value which triggers SQL buffer truncation due to length inconsistencies between variables.
Reference
http://lists.grok.org.uk/pipermail/full-disclosure/2007-July/064676.html http://secunia.com/advisories/26018 http://securityreason.com/securityalert/2895 http://www.sec-1labs.co.uk/advisories/BTA_Full.pdf http://www.securityfocus.com/bid/24936
Share on: