Lucene search

K
cve[email protected]CVE-2010-1132
HistoryMar 27, 2010 - 7:07 p.m.

CVE-2010-1132

2010-03-2719:07:11
CWE-78
web.nvd.nist.gov
31
cve-2010-1132
spamassassin
milter plugin
remote code execution
email security
vulnerability

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.188 Low

EPSS

Percentile

96.3%

The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.

Affected configurations

NVD
Node
georg_grevespamassassin_milter_pluginMatch0.3.1

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.188 Low

EPSS

Percentile

96.3%