CVE-2007-3796

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/07/2007
Last modified:
09/04/2025

Description

The password reset feature in the Spam Quarantine HTTP interface for MailMarshal SMTP 6.2.0.x before 6.2.1 allows remote attackers to modify arbitrary account information via a UserId variable with a large amount of trailing whitespace followed by a malicious value, which triggers SQL buffer truncation due to length inconsistencies between variables.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mailmarshal:mailmarshal_smtp:*:*:*:*:*:*:*:* 6.2.0 (including)