Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2002-2423

EPSS 0.30% · P53
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2002-2423

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address from being logged via a long IDENT response.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Sendmail超长Ident日志记录欺骗漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Sendmail是一款免费开放源代码邮件传输代理,由Sendmail Consortium开发和维护。 Sendmail没有正确处理超长idents,远程攻击者可以利用这个漏洞执行多个Sendmail命令而不被记录IP信息。 当使用95字节或者更长的ident数据连接Sendmail时,Sendmail由于会因为有超过所定义的缓冲区长度而截断提交请求IP的信息,而导致攻击者在使用VRFY、EXPN、SMTP攻击或者发送EMAIL,其IP地址不会被记录在maillog日志中。 这个问题不存在执行任意代码的可
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2002-2423

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2002-2423

登录查看更多情报信息。

Same Patch Batch · n/a · 2007-11-01 · 55 CVEs total

CVE-2007-5776Blue-Collar Productions i-Gallery igallery.ASP 目录遍历漏洞
CVE-2007-5791Vonage Motorola VT 2142用户身份伪造漏洞
CVE-2007-5786GoSamba 多个远程文件包含漏洞
CVE-2007-5789Grandstream HandyTone-488 PSTN To VoIP适配器IP栈远程拒绝服务漏洞
CVE-2007-5788Grandstream HandyTone-488 PSTN-to-VoIP适配器远程溢出漏洞
CVE-2007-5787Micro Login System UserPWD.TXT 信息泄露漏洞
CVE-2007-5790Globe7 SIP软件电话弱口令混淆漏洞
CVE-2007-5779Gretech GOM Player GomWeb3.dll远程栈溢出漏洞
CVE-2007-5778Mobile Spy Insecure Password Storage 信息泄露漏洞
CVE-2007-5777Blue-Collar Blue-Collar Productions I-Gallery web根目录 权限许可和访问控制漏洞
CVE-2007-5780Teatro pub08_comments.php 远程文件包含漏洞
CVE-2007-5775BitDefender在线扫描器OScan.OCX ActiveX控件堆溢出漏洞
CVE-2007-5774Flatnuke3 文件管理模块index.php 信息泄露漏洞
CVE-2007-5773Flatnuke index.php 跨站请求伪造漏洞
CVE-2007-5772Flatnuke3 文件管理模块 未授权访问漏洞
CVE-2007-5771Flatnuke3 myforum%00 cookie 权限绕过漏洞
CVE-2007-5793多个IDS产品全角/半角Unicode编码检测漏报漏洞
CVE-2002-2425Sun AnswerBook2未认证管理脚本访问漏洞
CVE-2002-2424PHPReactor样式属性HTML注入漏洞
CVE-2002-2422HP Compaq Insight Manager Web界面跨站脚本漏洞

Showing top 20 of 55 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2002-2423

No comments yet


Leave a comment