PT-2001-1260 · Unknown · Simplestmail.Cgi

Published

2001-02-02

·

Updated

2017-12-19

·

CVE-2001-0024

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: simplestmail.cgi (affected versions not specified)
Description: The simplestmail.cgi CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the MyEmail parameter. This issue can be exploited by sending malicious input to the CGI program, potentially leading to unauthorized access and command execution.
Recommendations: As a temporary workaround, consider restricting access to the simplestmail.cgi program until a patch is available. Avoid using the MyEmail parameter in the simplestmail.cgi program until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0024

Affected Products

Simplestmail.Cgi