9.3
CVSSv2

CVE-2006-5177

Published: 10/10/2006 Updated: 20/07/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote malicious users to (1) execute arbitrary code via unspecified vectors involving crafted base64 encoded NTLM Type 3 messages, or (2) cause a denial of service via crafted base64 encoded NTLM Type 1 messages, which trigger a buffer over-read.

Vulnerable Product Search on Vulmon Subscribe to Product

mailenable mailenable enterprise 2.0

mailenable mailenable professional 2.0

Exploits

source: wwwsecurityfocuscom/bid/20290/info MailEnable is prone to multiple remote vulnerabilities These issues arise in the SMTP server during NTLM authentication and may facilitate arbitrary code execution or denial-of-service conditions MailEnable Professional 20 and MailEnable Enterprise 20 are reported vulnerable to these issue ...