GNU Mailman Empty Password Blank...

- AV AC AU C I A
发布: 2001-09-05
修订: 2025-04-13

GNU Mailman is a freely available, open source mailing list manager written in Python, and maintained by public domain. A problem has been discovered in GNU Mailman that can allow users arbitrary access to accounts. When a password file has been created, but left blank, it is possible for a remote user to gain access to a user account as by entering an arbitrary password of any type. This is due to a bug in the crypt function, which upon receiving a blank salt, will return a blank hash.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息