Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-1251

Опубликовано: 19 мар. 2006
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sa-exim:sa-exim:4.0:*:*:*:*:*:*:*
cpe:2.3:a:sa-exim:sa-exim:4.1:*:*:*:*:*:*:*
cpe:2.3:a:sa-exim:sa-exim:4.2:*:*:*:*:*:*:*

EPSS

Процентиль: 71%
0.00687
Низкий

5 Medium

CVSS2

Дефекты

CWE-94

Связанные уязвимости

ubuntu
больше 19 лет назад

Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.

debian
больше 19 лет назад

Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 ...

github
больше 3 лет назад

Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.

EPSS

Процентиль: 71%
0.00687
Низкий

5 Medium

CVSS2

Дефекты

CWE-94