JamMail Jammail.pl Remote Arbitrary Command Execution Vulnerability
BID:13937
Info
JamMail Jammail.pl Remote Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 13937 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2005 12:00AM |
| Updated: | Jun 12 2005 12:00AM |
| Credit: | Discovery is credited to blahplok. |
| Vulnerable: |
JamMail JamMail 1.8 |
| Not Vulnerable: | |
Discussion
JamMail Jammail.pl Remote Arbitrary Command Execution Vulnerability
JamMail is prone to a remote arbitrary command execution vulnerability.
This vulnerability may allow an attacker to supply arbitrary commands through the 'jammail.pl' script.
This can lead to various attacks including unauthorized access to an affected computer.
JamMail 1.8 is affected by this issue.
JamMail is prone to a remote arbitrary command execution vulnerability.
This vulnerability may allow an attacker to supply arbitrary commands through the 'jammail.pl' script.
This can lead to various attacks including unauthorized access to an affected computer.
JamMail 1.8 is affected by this issue.
Exploit / POC
JamMail Jammail.pl Remote Arbitrary Command Execution Vulnerability
An exploit is not required.
The following proof of concept is available:
http://www.example.com/cgi-bin/jammail.pl?job=showoldmail&mail=|command|
An exploit is not required.
The following proof of concept is available:
http://www.example.com/cgi-bin/jammail.pl?job=showoldmail&mail=|command|
Solution / Fix
JamMail Jammail.pl Remote Arbitrary Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
JamMail Jammail.pl Remote Arbitrary Command Execution Vulnerability
References:
References: