Real Name | Thomas Henlich |
---|---|
Email address | thomas at henlich.de |
First Active | 2005-10-21 |
Last Active | 2006-01-08 |
A file inclusion vulnerability exists in WebFTP version 1.2.6 in webftp.php.
5be93b7e1c3861a44e8fd2e42aaf49adbbcf18c9cfd4ded89e929284fa6939f2
Mozilla Thunderbird SMTP down-negotiation behavior allows a man-in-the-middle (MITM) attack to bypass TLS initialization and/or downgrade CRAM-MD5 to PLAIN authentication, leading to exposure of authentication information. Failure in CRAM-MD5 authentication also leads to exposure of authentication information to a passive eavesdropper. Affected versions: Mozilla Thunderbird 1.0.7 (20050923), Mozilla Thunderbird 1.5 Beta 2 (20051006), possibly other programs using the Mozilla mail component.
d7c2c62f53981de1b1e61fbb11de9278cff73769ab86c648b175814f320ba698
Mozilla Thunderbird SMTP down-negotiation behavior allows a man- in-the-middle (MITM) attack to bypass TLS initialization and/or downgrade CRAM-MD5 to PLAIN authentication, leading to exposure of authentication information. Failure in CRAM-MD5 authentication also leads to exposure of authentication information to a passive eavesdropper.
45fbeadf936771da0e38eba38836f70be1b8a427bb908f4c6addba8fc4fef977