Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2014-2727

Disclosure Date: February 19, 2020 (last updated February 21, 2025)
The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.
Attacker Value
Unknown

CVE-2007-3796

Disclosure Date: July 17, 2007 (last updated October 04, 2023)
The password reset feature in the Spam Quarantine HTTP interface for MailMarshal SMTP 6.2.0.x before 6.2.1 allows remote attackers to modify arbitrary account information via a UserId variable with a large amount of trailing whitespace followed by a malicious value, which triggers SQL buffer truncation due to length inconsistencies between variables.
0
Attacker Value
Unknown

CVE-2006-5487

Disclosure Date: November 10, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in Marshal MailMarshal SMTP 5.x, 6.x, and 2006, and MailMarshal for Exchange 5.x, allows remote attackers to write arbitrary files via ".." sequences in filenames in an ARJ compressed archive.
0