Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
class.xmail.php in PhpXmail 0.7 through 1.1 does not properly handle large passwords, which prevents an error message from being returned and allows remote attackers to bypass authentication and gain unauthorized access.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHPXmail class.xmail.php 绕过身份认证漏洞
Vulnerability Description
PHPXmail是基于Web的Xmail邮件服务器管理软件,用PHP语言编写。 PHPXmail 0.7至1.1版本中的class.xmail.php中存在绕过身份认证漏洞。 由于不能正确处理超长的用户密码,在出错后不会返回错误信息,这使得远程攻击者可利用此漏洞绕过身份认证,进行非授权访问。
CVSS Information
N/A
Vulnerability Type
N/A