CVE-2008-6984: Medium severity plesk obsidian vulnerability
Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname, or (2) a username that matches a valid password, as demonstrated using (a) SMTP and qmail, and (b) Courier IMAP and POP3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6984?
CVE-2008-6984 has a moderate severity level due to its ability to allow remote attackers to bypass authentication.
How do I fix CVE-2008-6984?
To fix CVE-2008-6984, upgrade to a newer version of Plesk that addresses this vulnerability.
What systems are impacted by CVE-2008-6984?
CVE-2008-6984 specifically affects Plesk version 8.6.0 on both Windows and Linux/Unix platforms.
Can CVE-2008-6984 be exploited remotely?
Yes, CVE-2008-6984 can be exploited remotely by attackers to send spam emails.
What type of attacks are possible due to CVE-2008-6984?
CVE-2008-6984 allows attackers to send spam emails by bypassing authentication through specific username manipulations.