Zeta Components Mail CVE-2017-15806 Arbitrary Code Execution Vulnerability
BID:101866
Info
Zeta Components Mail CVE-2017-15806 Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 101866 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-15806 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 15 2017 12:00AM |
| Updated: | Dec 19 2017 10:37PM |
| Credit: | Kay. |
| Vulnerable: |
Zeta Components Mail 1.8 |
| Not Vulnerable: |
Zeta Components Mail 1.8.2 |
Discussion
Zeta Components Mail CVE-2017-15806 Arbitrary Code Execution Vulnerability
Zeta Components Mail is prone to an arbitrary code execution vulnerability.
Successful exploits allow attackers to execute arbitrary code in the context of the host operating system. Failed exploit attempts will result in a denial of service condition.
Zeta Components Mail prior to 1.8.2 are vulnerable.
Zeta Components Mail is prone to an arbitrary code execution vulnerability.
Successful exploits allow attackers to execute arbitrary code in the context of the host operating system. Failed exploit attempts will result in a denial of service condition.
Zeta Components Mail prior to 1.8.2 are vulnerable.
Exploit / POC
Zeta Components Mail CVE-2017-15806 Arbitrary Code Execution Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Zeta Components Mail CVE-2017-15806 Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.