CVE-2002-1582
Summary
| CVE | CVE-2002-1582 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-06 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | compose.cgi in Mailreader.com 2.3.30 and 2.3.31, when using Sendmail as the Mail Transfer Agent, allows remote attackers to execute arbitrary commands via shell metacharacters in the RealEmail configuration variable, which is used to call Sendmail in network.cgi. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mailreader.com | Mailreader.com | 2.3.30 | All | All | All |
| Application | Mailreader.com | Mailreader.com | 2.3.31 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 's by request of one Anthony DiSante * A fixed Dutch translation by Almar van Pel * Added ALT's to all -tags by request of Raul A. Gallegos * Possibility to use the sendmail binary instead of SMTP by Mark Slemko * Cookie-based session identification for those browsers that accept cookies (a fix for a nasty security bug) * A workaround for an IIS bug for a piece of code that was originally put in there to work around IE bugs :-) 2.3.29 Thu Jul 19 09:37 2001 Kim Holviala * Uh... .27 and .2 | af854a3a-2127-422b-91ae-364da2661108 | www.mailreader.com | Vendor Advisory |
| ISS X-Force Database: mailreader-compose-command-execution (10491): Mailreader.com compose.cgi script could allow an attacker to execute commands | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Patch, Vendor Advisory |
| MailReader.com Remote Command Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.