CVE-2007-3796 - CVE House
Back to Database
Status published High CVE-2007-3796

The password reset feature in the Spam Quarantine HTTP interface...

Vulnerability Description

The password reset feature in the Spam Quarantine HTTP interface for MailMarshal SMTP 6.2.0.x before 6.2.1 allows remote attackers to modify arbitrary account information via a UserId variable with a large amount of trailing whitespace followed by a malicious value, which triggers SQL buffer truncation due to length inconsistencies between variables.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-3796

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

mailmarshal

View all reports →

Affected Software

mailmarshal smtp
Vulnerable Versions:
0

Timeline

Official Publish: July 17th, 2007
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.