Title : DBMail Authldap Module Remote Authentication Bypass Vulnerability VUPEN ID : VUPEN/ADV-2008-1321 CVE ID : CVE-2007-6714
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-23
Technical Description
A vulnerability has been identified in DBMail, which could be exploited by attackers to bypass security checks. This issue is caused by an error in the Authldap module (modules/authldap.c) when handling empty passwords, which could be exploited by unauthenticated attackers to gain unauthorized access to certain LDAP implementations.