vendor:
WinWebMail
by:
Matteo Memelli aka ryujin
7.5
CVSS
HIGH
Denial-of-Service
400
CWE
Product Name: WinWebMail
Affected Version From: 3.7.3.2
Affected Version To: 3.7.3.2
Patch Exists: YES
Related CWE: N/A
CPE: a:winwebmail:winwebmail
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XPSP2 English
2008
WinWebMail Denial-of-Service Vulnerability
WinWebMail is prone to a denial-of-service vulnerability because it fails to perform adequate boundary checks on user-supplied input. Remote attackers can exploit this issue to crash the server and deny service to legitimate users. Given the nature of this issue, attackers may also be able to execute arbitrary code, but this has not been confirmed.
Mitigation:
Ensure that boundary checks are performed on user-supplied input.