Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2001-0990
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Inter7 vpopmail MySQL 认证数据恢复漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
CVE(CAN) ID: CAN-2001-0990 Inter7 vpopmail是一款免费软件包,它为系统管理员提供了管理虚拟Email域名和 Qmail或Postfix服务器上的非系统的Email密码提供了方便。 如果我们把vpopmail配置为使用MySql数据库的话,就可能导致敏感认证信息的泄露。 这是因为MySql数据库密码被明文存储在库文件"libvpopmail.a"中,而vpopmail所带 的几个命令行程序都用到了这个库文件,因此也就相当于包含了这个密码,而这些命令 行程序都是全局可读
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
-n/a n/a -
II. Public POCs for CVE-2001-0990
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2001-0990
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2001-0990

No comments yet


Leave a comment