6.8
CVSSv2

CVE-2008-1218

Published: 10/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Argument injection vulnerability in Dovecot 1.0.x prior to 1.0.13, and 1.1.x prior to 1.1.rc3, when using blocking passdbs, allows remote malicious users to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified.

Vulnerable Product Search on Vulmon Subscribe to Product

dovecot dovecot

Vendor Advisories

It was discovered that the default configuration of dovecot could allow access to any email files with group “mail” without verifying that a user had valid rights An attacker able to create symlinks in their mail directory could exploit this to read or delete another user’s email (CVE-2008-1199) ...

Exploits

#lame Dovecot IMAP [1010 -> 11rc3] Exploit #Here's an exploit for the recent TAB vulnerability in Dovecot #It's nothing special since in the wild there are few to none #targets because of the special option which has to be set #see CVE Entry CVE-2008-1218 #Exploit written by Kingcope import sys import imaplib print "Dovecot IMAP [1010 -& ...
Dovecot IMAP versions 1010 through 11rc2 remote email disclosure exploit ...