Vulnerabilities > CVE-2003-0266 - Unspecified vulnerability in Bvrp Software Slwebmail 3.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN bvrp-software
nessus
Summary
Multiple buffer overflows in SLWebMail 3 on Windows systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long Language parameter to showlogin.dll, (2) a long CompanyID parameter to recman.dll, (3) a long CompanyID parameter to admin.dll, or (4) a long CompanyID parameter to globallogin.dll.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | CGI abuses |
NASL id | SLMAIL_WEBMAIL_FLAWS.NASL |
description | The remote host is running a version of the SLmail WebMail server which is vulnerable to various flaws. These flaws may let a user to execute arbitrary code on this host or read arbitrary files. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11596 |
published | 2003-05-07 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11596 |
title | SLMail WebMail Multiple Remote Overflows |
code |
|
References
- http://marc.info/?l=bugtraq&m=105232436210273&w=2
- http://marc.info/?l=bugtraq&m=105232436210273&w=2
- http://marc.info/?l=ntbugtraq&m=105233363721919&w=2
- http://marc.info/?l=ntbugtraq&m=105233363721919&w=2
- http://www.nextgenss.com/advisories/slwebmail-vulns.txt
- http://www.nextgenss.com/advisories/slwebmail-vulns.txt