PT-2019-18359 · Titanhq · Spamtitan
Publicado
2019-06-05
·
Atualizado
2019-06-06
·
CVE-2019-6800
CVSS v2.0
8.5
Alta
| Vetor | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TitanHQ SpamTitan versions 7.03 and earlier
Description
A vulnerability exists in the spam rule update function of the affected software. Updates are downloaded over HTTP, including scripts that are subsequently executed with root permissions. This allows an attacker with a privileged network position to inject arbitrary commands.
Recommendations
For TitanHQ SpamTitan versions 7.03 and earlier, consider disabling the spam rule update function until a secure update mechanism is implemented, and restrict access to the update process to minimize the risk of exploitation.
Exploit
Correção
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Spamtitan