CVE-2007-3275
Estado: ModificadaAlta (7.1)—
MailWasher Server before 2.2.1, when used with LDAP or Active Directory (AD), does not properly handle blank passwords, which allows remote attackers to access an arbitrary user account and read the spam e-mail messages stored for that account, possibly related to the LoginCheck::doPost function in mwi/servlet/Login.cpp. NOTE: some of these details are obtained from third party information.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.49%
- Percentil entre todas las CVEs puntuadas: 73
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-255
Referencias
- http://osvdb.org/37538
- http://secunia.com/advisories/25695
- http://sourceforge.net/project/shownotes.php?release_id=515127
- http://www.securityfocus.com/bid/24507
- http://www.vupen.com/english/advisories/2007/2239
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34925
- http://osvdb.org/37538
- http://secunia.com/advisories/25695
- http://sourceforge.net/project/shownotes.php?release_id=515127
- http://www.securityfocus.com/bid/24507
- http://www.vupen.com/english/advisories/2007/2239
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34925
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-3275",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.1,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-06-19T21:30:00.000",
"references": [
{
"url": "http://osvdb.org/37538",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/25695",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://sourceforge.net/project/shownotes.php?release_id=515127",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/24507",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/2239",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34925",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/37538",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/25695",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://sourceforge.net/project/shownotes.php?release_id=515127",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/24507",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/2239",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34925",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-255"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "MailWasher Server before 2.2.1, when used with LDAP or Active Directory (AD), does not properly handle blank passwords, which allows remote attackers to access an arbitrary user account and read the spam e-mail messages stored for that account, possibly related to the LoginCheck::doPost function in mwi/servlet/Login.cpp. NOTE: some of these details are obtained from third party information."
},
{
"lang": "es",
"value": "MailWasher Server versiones anteriores a 2.2.1, cuando es usado con LDAP o Active Directory (AD), no maneja apropiadamente las contraseñas en blanco, lo que permite a atacantes remotos acceder a una cuenta de usuario arbitraria y leer los mensajes de correo electrónico de tipo spam almacenados posiblemente relacionados con la función LoginCheck::doPost en el archivo mwi/servlet/Login.cpp. NOTA: algunos de estos datos son obtenidos a partir de información de terceros."
}
],
"lastModified": "2026-06-16T22:41:24.067",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mailwasher:mailwasher_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D77B45EB-7ABD-45C7-9FA5-A011F351272B",
"versionEndIncluding": "2.2.0"
}
],
"operator": "OR"
}
]
}
],
"evaluatorImpact": "Successful exploitation requires knowledge of a valid username and that MailWasher Server is integrated into an AD domain or LDAP repository.",
"sourceIdentifier": "cve@mitre.org"
}