PT-2020-12785 · Titanhq · Spamtitan

Felipe Molina

·

Published

2020-09-17

·

Updated

2022-04-28

·

CVE-2020-11698

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SpamTitan version 7.07
Description An issue was discovered in SpamTitan where improper input sanitization of the parameter community on the page "snmp-x.php" would allow a remote attacker to inject commands into the file "snmpd.conf", enabling the execution of commands on the target server.
Recommendations For SpamTitan version 7.07, ensure proper input sanitization of the community parameter in the "snmp-x.php" page to prevent command injection. As a temporary workaround, consider restricting access to the "snmp-x.php" page until a fix is available.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11698

Affected Products

Spamtitan