Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-6714
Description:DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which causes the LDAP bind to indicate success based on anonymous authentication.
Test IDs: 1.3.6.1.4.1.25623.1.0.60824   1.3.6.1.4.1.25623.1.0.60911   1.3.6.1.4.1.25623.1.0.860589   1.3.6.1.4.1.25623.1.0.60918   1.3.6.1.4.1.25623.1.0.860829   1.3.6.1.4.1.25623.1.0.860447   1.3.6.1.4.1.25623.1.0.61015  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-6714
BugTraq ID: 28849
http://www.securityfocus.com/bid/28849
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00549.html
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00585.html
http://www.gentoo.org/security/en/glsa/glsa-200804-24.xml
http://www.mail-archive.com/dbmail-dev@dbmail.org/msg09942.html
http://osvdb.org/44561
http://www.securitytracker.com/id?1019914
http://secunia.com/advisories/29903
http://secunia.com/advisories/29937
http://secunia.com/advisories/29984
http://www.vupen.com/english/advisories/2008/1321/references
XForce ISS Database: dbmail-authldap-security-bypass(41907)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41907




© 1998-2025 E-Soft Inc. All rights reserved.