PT-2001-1500 · Unknown · Mailnews.Cgi
Publicado
2001-04-04
·
Atualizado
2008-09-05
·
CVE-2001-0271
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
mailnews.cgi version 1.3 and earlier
Description
The issue allows remote attackers to execute arbitrary commands via a user name that contains shell metacharacters.
Recommendations
For mailnews.cgi version 1.3 and earlier, update to a version later than 1.3 to resolve the issue. As a temporary workaround, consider validating and sanitizing user input to prevent the inclusion of shell metacharacters in user names.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mailnews.Cgi