Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-1516

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2005-1516
Last Modified 05 Sep 2008 04:49:22
Published 11 May 2005 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2005-1516

Summary

DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog command with an incorrect password hash, which is not properly handled by the _cmd_sendlog function.

Vulnerable Systems

Application

  • Netwin Dmail 3.1a


References

XF - dmail-dlist-bypass-authentication(20412)

BID - 13497

MISC - http://www.security.org.sg/vuln/dmail31a.html

SECUNIA - 15242


Last Updated: 27 May 2016 10:40:12