nginx SMTP Proxy Remote Command Injection Vulnerability
BID:69111
Info
nginx SMTP Proxy Remote Command Injection Vulnerability
| Bugtraq ID: | 69111 |
| Class: | Design Error |
| CVE: |
CVE-2014-3556 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 07 2014 12:00AM |
| Updated: | Aug 07 2014 12:00AM |
| Credit: | Chris Boulton |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
nginx SMTP Proxy Remote Command Injection Vulnerability
nginx is prone to a remote command-injection vulnerability.
Attackers can exploit this issue to inject commands into SSL sessions and disclose sensitive information.
Versions prior to nginx 1.6.1 and 1.7.4 are vulnerable.
nginx is prone to a remote command-injection vulnerability.
Attackers can exploit this issue to inject commands into SSL sessions and disclose sensitive information.
Versions prior to nginx 1.6.1 and 1.7.4 are vulnerable.
Exploit / POC
nginx SMTP Proxy Remote Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].