vpopmail-CGIApps 'vpasswd.cgi'...

- AV AC AU C I A
发布: 2002-10-24
修订: 2025-04-13

A remote command execution vulnerability has been discovered in vpopmail-CGIApps v0.2. Due to insufficient sanitization of user-supplied input in vpasswd.cgi, it is possible to pass malicious commands to the os.system() function. Exploiting this issue allows a remote attacker to execute arbitrary system commands with the permissions of the web server.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息