5
CVSSv2

CVE-2001-1075

Published: 04/07/2001 Updated: 10/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

poprelayd script prior to 2.0 in Cobalt RaQ3 servers allows remote malicious users to bypass authentication for relaying by causing a "POP login by user" string that includes the attacker's IP address to be injected into the maillog log file.

Vulnerable Product Search on Vulmon Subscribe to Product

sun cobalt raq 3i

Exploits

source: wwwsecurityfocuscom/bid/2986/info poprelayd is a script that parses /var/log/maillog for valid pop logins, and based upon the login of a client, allows the person logged into the pop3 service to also send email from the ip address they're accessing the system with poprelayd doesn't authenticate output to the /var/log/maillog fil ...