DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which causes the LDAP bind to indicate success based on anonymous authentication.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2008-04-17T22:00:00

Updated: 2024-08-07T16:18:20.530Z

Reserved: 2008-04-17T00:00:00

Link: CVE-2007-6714

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2008-04-17T22:05:00.000

Modified: 2024-11-21T00:40:49.747

Link: CVE-2007-6714

cve-icon Redhat

Severity : Moderate

Publid Date: 2007-12-16T00:00:00Z

Links: CVE-2007-6714 - Bugzilla