vendor:
SmarterMail
by:
Matteo Memelli aka ryujin
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: SmarterMail
Affected Version From: 5
Affected Version To: 5
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XPSP2 English
2008
SmarterTools SmarterMail Denial of Service Vulnerability
SmarterTools SmarterMail is prone to a denial-of-service vulnerability when handling specially crafted HTTP GET, HEAD, PUT, POST, and TRACE requests. When the server eventually resets the request connection, it will crash. Remote attackers can exploit this issue to deny service to legitimate users.
Mitigation:
Upgrade to the latest version of SmarterMail.