{"api_version":"1","generated_at":"2026-07-23T09:07:32+00:00","cve":"CVE-2002-1582","urls":{"html":"https://cve.report/CVE-2002-1582","api":"https://cve.report/api/cve/CVE-2002-1582.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-1582","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-1582"},"summary":{"title":"CVE-2002-1582","description":"compose.cgi in Mailreader.com 2.3.30 and 2.3.31, when using Sendmail as the Mail Transfer Agent, allows remote attackers to execute arbitrary commands via shell metacharacters in the RealEmail configuration variable, which is used to call Sendmail in network.cgi.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-06 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.mailreader.com/download/ChangeLog","name":"http://www.mailreader.com/download/ChangeLog","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"'s by request of one Anthony DiSante\n\t* A fixed Dutch translation by Almar van Pel\n\t* Added ALT's to all -tags by request of Raul A. Gallegos\n\t* Possibility to use the sendmail binary instead of SMTP by Mark Slemko\n\t* Cookie-based session identification for those browsers that\n\t  accept cookies (a fix for a nasty security bug)\n\t* A workaround for an IIS bug for a piece of code that was originally\n\t  put in there to work around IE bugs  :-)\n\n\n2.3.29  Thu Jul 19 09:37 2001  Kim Holviala  \n\n\t* Uh... .27 and .2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/10491.php","name":"http://www.iss.net/security_center/static/10491.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"ISS X-Force Database: mailreader-compose-command-execution (10491): Mailreader.com compose.cgi script could allow an attacker to execute commands","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/6058","name":"http://www.securityfocus.com/bid/6058","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"MailReader.com Remote Command Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/297428","name":"http://www.securityfocus.com/archive/1/297428","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-1582","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-1582","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"1582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mailreader.com","cpe5":"mailreader.com","cpe6":"2.3.30","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mailreader.com","cpe5":"mailreader.com","cpe6":"2.3.31","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:26:29.334Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"mailreader-compose-command-execution(10491)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/10491.php"},{"name":"6058","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6058"},{"name":"20021028 SCAN Associates Advisory : Multiple vurnerabilities on mailreader.com","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/297428"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mailreader.com/download/ChangeLog"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-10-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"compose.cgi in Mailreader.com 2.3.30 and 2.3.31, when using Sendmail as the Mail Transfer Agent, allows remote attackers to execute arbitrary commands via shell metacharacters in the RealEmail configuration variable, which is used to call Sendmail in network.cgi."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2021-06-15T16:37:16.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"mailreader-compose-command-execution(10491)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/10491.php"},{"name":"6058","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6058"},{"name":"20021028 SCAN Associates Advisory : Multiple vurnerabilities on mailreader.com","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/297428"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mailreader.com/download/ChangeLog"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-1582","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"compose.cgi in Mailreader.com 2.3.30 and 2.3.31, when using Sendmail as the Mail Transfer Agent, allows remote attackers to execute arbitrary commands via shell metacharacters in the RealEmail configuration variable, which is used to call Sendmail in network.cgi."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"mailreader-compose-command-execution(10491)","refsource":"XF","url":"http://www.iss.net/security_center/static/10491.php"},{"name":"6058","refsource":"BID","url":"http://www.securityfocus.com/bid/6058"},{"name":"20021028 SCAN Associates Advisory : Multiple vurnerabilities on mailreader.com","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/297428"},{"name":"http://www.mailreader.com/download/ChangeLog","refsource":"CONFIRM","url":"http://www.mailreader.com/download/ChangeLog"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-1582","datePublished":"2004-07-06T04:00:00.000Z","dateReserved":"2004-06-30T00:00:00.000Z","dateUpdated":"2024-08-08T03:26:29.334Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-06 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mailreader.com:mailreader.com:2.3.30:*:*:*:*:*:*:*","matchCriteriaId":"0A37F7F2-C147-4D04-83D0-421EDB1EF343"},{"vulnerable":true,"criteria":"cpe:2.3:a:mailreader.com:mailreader.com:2.3.31:*:*:*:*:*:*:*","matchCriteriaId":"19CC1D27-027D-4032-B9CC-CD41ED085FD0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"1582","Ordinal":"1","Title":"CVE-2002-1582","CVE":"CVE-2002-1582","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"1582","Ordinal":"1","NoteData":"compose.cgi in Mailreader.com 2.3.30 and 2.3.31, when using Sendmail as the Mail Transfer Agent, allows remote attackers to execute arbitrary commands via shell metacharacters in the RealEmail configuration variable, which is used to call Sendmail in network.cgi.","Type":"Description","Title":"CVE-2002-1582"},{"CveYear":"2002","CveId":"1582","Ordinal":"2","NoteData":"2004-07-06","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"1582","Ordinal":"3","NoteData":"2021-06-15","Type":"Other","Title":"Modified"}]}}}