PT-2004-1134 · Mailreader.Com+1 · Mailreader.Com+1

Publicado

2004-07-06

·

Atualizado

2008-09-05

·

CVE-2002-1582

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mailreader.com versions 2.3.30 through 2.3.31
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in the RealEmail configuration variable, which is used to call Sendmail. This is specifically a problem when Sendmail is used as the Mail Transfer Agent.
Recommendations For Mailreader.com versions 2.3.30 and 2.3.31, consider restricting the use of the RealEmail configuration variable until a patch is available. As a temporary workaround, avoid using shell metacharacters in the RealEmail variable to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1582

Produtos afetados

Mailreader.Com
Sendmail