10
CVSSv2

CVE-2001-0192

Published: 03/05/2001 Updated: 05/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflows in CTRLServer in XMail allows malicious users to execute arbitrary commands via the cfgfileget or domaindel functions.

Vulnerable Product Search on Vulmon Subscribe to Product

davide libenzi xmail

Exploits

source: wwwsecurityfocuscom/bid/2360/info Versions of CTRLServer are vulnerable to malicious user-supplied input A failure to properly bounds-check data passed to the cfgfileget() command leads to an overflow, which, properly exploited, can result in remote execution of malicious code with root privilege /* * XMail CTRLServer remote ...