CVE-2007-6714
DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which causes the LDAP bind to indicate success based on anonymous authentication.
- Affected products
- Active Directory, Dbmail
- Dbmail
- = 2.2.6, 2.2.7, 2.2.8
- Fix
- Available
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 2.4% (83th percentile)
- Weakness
- CWE-287
- NVD status
- Modified
- Published
- 2008-04-17
CVE-2007-6714 at NVD
1 known exploit for CVE-2007-6714
Proof-of-concept code and exploit modules indexed by Sploitus