Описание
MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s access token.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:openfind:mailaudit:4.0:*:*:*:*:*:*:*
cpe:2.3:a:openfind:mailaudit:5.0:*:*:*:*:*:*:*
cpe:2.3:a:openfind:mailgates:4.0:*:*:*:*:*:*:*
cpe:2.3:a:openfind:mailgates:5.0:*:*:*:*:*:*:*
EPSS
Процентиль: 86%
0.02985
Низкий
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-78
CWE-78
Связанные уязвимости
github
больше 3 лет назад
MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s access token.
EPSS
Процентиль: 86%
0.02985
Низкий
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-78
CWE-78