Описание
In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. An attacker with a privileged network position is trivially able to inject arbitrary commands.
Ссылки
- ExploitThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 7.00 (включая) до 7.03 (включая)
cpe:2.3:a:titanhq:spamtitan:*:*:*:*:*:*:*:*
EPSS
Процентиль: 71%
0.00689
Низкий
7.5 High
CVSS3
8.5 High
CVSS2
Дефекты
CWE-74
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. An attacker with a privileged network position is trivially able to inject arbitrary commands.
EPSS
Процентиль: 71%
0.00689
Низкий
7.5 High
CVSS3
8.5 High
CVSS2
Дефекты
CWE-74