Mailnews.cgi Username Remote Shell...

- AV AC AU C I A
发布: 2001-02-18
修订: 2025-04-13

Mailnews.cgi fails to check remote user-supplied input for shell metacharacters. A remote attacker can insert a new user to the mailnews' user file which includes malicious shell commands in the username field. Upon displaying this this data, the embedded commands will execute with the privileges of the webserver process.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息