CVE Database
/

CVE-2008-6984

Back to search

CVE-2008-6984

Published: Aug 18, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname, or (2) a username that matches a valid password, as demonstrated using (a) SMTP and qmail, and (b) Courier IMAP and POP3.

VendorProductVersions

n/a

n/a

affected
n/a

References

1020801
vdb-entry
x_refsource_SECTRACK
30956
vdb-entry
x_refsource_BID
51652
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now