7.5
CVSSv2

CVE-2001-0400

Published: 02/07/2001 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

nph-maillist.pl allows remote malicious users to execute arbitrary commands via shell metacharacters ("`") in the email address.

Vulnerable Product Search on Vulmon Subscribe to Product

matt tourtillott nph-maillist 3.0

matt tourtillott nph-maillist 3.5

Exploits

source: wwwsecurityfocuscom/bid/2563/info nph-maillist is a Perl CGI script that handles mailing lists, typically used to notify interested users of site updates A hostile user can enter commands embedded in an email address via the subscription form, and then force a mailing which will execute the commands #!/usr/bin/perl # nph-maill ...