The MailMarshal Spam Quarantine version 6.2.0.x HTTP interface password reset facility is vulnerable to a SQL buffer truncation attack. The vulnerability could be exploited to reset and retrieve any user account. The attacker would require prior knowledge of the users email address.
413e168c92dfcc339ecd500754b6e240ebd1b59e709f687e96ac02bb9c73e549