CVE-2008-6984
Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname, or (2) a username that matches…
Does this matter?
Lower severity and a low EPSS score (1.35%). Track it; it rarely justifies an emergency change on its own.
Description
Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname, or (2) a username that matches a valid password, as demonstrated using (a) SMTP and qmail, and (b) Courier IMAP and POP3.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 1.35% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- parallels/plesk
- Source
- cve@mitre.org
References
- http://www.osvdb.org/51652
- http://www.securityfocus.com/archive/1/495881Exploit
- http://www.securityfocus.com/bid/30956
- http://www.securitytracker.com/id?1020801
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44856
- http://www.osvdb.org/51652
- http://www.securityfocus.com/archive/1/495881Exploit
- http://www.securityfocus.com/bid/30956
- http://www.securitytracker.com/id?1020801
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44856
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.