PT-2004-1134 · Mailreader.Com+1 · Mailreader.Com+1
Publicado
2004-07-06
·
Atualizado
2008-09-05
·
CVE-2002-1582
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mailreader.com versions 2.3.30 through 2.3.31
Description
The issue allows remote attackers to execute arbitrary commands via shell metacharacters in the
RealEmail configuration variable, which is used to call Sendmail. This is specifically a problem when Sendmail is used as the Mail Transfer Agent.Recommendations
For Mailreader.com versions 2.3.30 and 2.3.31, consider restricting the use of the
RealEmail configuration variable until a patch is available. As a temporary workaround, avoid using shell metacharacters in the RealEmail variable to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mailreader.Com
Sendmail