Vulnerabilities
Vulnerable Software
Mailmarshal:  Security Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the delegated spam management feature in the Spam Quarantine Management (SQM) component in MailMarshal SMTP 6.0.3.8 through 6.3.0.0 allow user-assisted remote authenticated users to inject arbitrary web script or HTML via (1) the list of blocked senders or (2) the list of safe senders.
CVSS Score
3.5
EPSS Score
0.003
Published
2008-10-02
The password reset feature in the Spam Quarantine HTTP interface for MailMarshal SMTP 6.2.0.x before 6.2.1 allows remote attackers to modify arbitrary account information via a UserId variable with a large amount of trailing whitespace followed by a malicious value, which triggers SQL buffer truncation due to length inconsistencies between variables.
CVSS Score
7.6
EPSS Score
0.009
Published
2007-07-17


Contact Us

Shodan ® - All rights reserved