Extremail 1.5.9 does not check passwords correctly when they are all digits or begin with a digit, which allows remote attackers to gain privileges.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/15329 | vdb entry |
http://www.securityfocus.com/bid/9754 | vdb entry vendor advisory |
http://marc.info/?l=bugtraq&m=107783767517850&w=2 | mailing list |