10
CVSSv2

CVE-2007-2188

Published: 24/04/2007 Updated: 13/11/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

eXtremail 2.1.1 and previous versions does not verify the ID field (aka transaction id) in DNS responses, which makes it easier for remote malicious users to conduct DNS spoofing.

Vulnerable Product Search on Vulmon Subscribe to Product

extremail extremail 2.1

extremail extremail 2.1.1