Vulnerabilities > CVE-2009-3749 - Unspecified vulnerability in Websense Email Security and Personal Email Manager
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allows remote attackers to cause a denial of service (crash) by sending a HTTP GET request to TCP port 8181 and closing the socket before the service can send a response.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | Websense Email Security DoS. CVE-2009-3749. Dos exploit for hardware platform |
id | EDB-ID:9980 |
last seen | 2016-02-01 |
modified | 2009-10-20 |
published | 2009-10-20 |
reporter | Nikolas Sotiriu |
source | https://www.exploit-db.com/download/9980/ |
title | Websense Email Security - DoS |
Nessus
NASL family | Windows |
NASL id | WEBSENSE_EMAIL_SECURITY_MULTIPLE_FLAWS.NASL |
description | Websense Email Security is installed on the remote host. The installed version is affected by multiple issues : - Websense Email Security Web Administrator service is affected by a denial of service issue. - Websense Email Security Web Administrator is affected by multiple cross-site scripting issues. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 42292 |
published | 2009-10-28 |
reporter | This script is Copyright (C) 2009-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/42292 |
title | Websense Email Security < 7.1 Hotfix 4 |
References
- http://kb.websense.com/display/4/kb/article.aspx?aid=4786
- http://secunia.com/advisories/37091
- http://sotiriu.de/adv/NSOADV-2009-002.txt
- http://www.securityfocus.com/bid/36740
- http://kb.websense.com/article.aspx?article=4786&p=12
- http://www.vupen.com/english/advisories/2009/2987
- http://www.securityfocus.com/archive/1/507329/100/0/threaded