4.6
CVSSv2

CVE-2002-1165

Published: 11/10/2002 Updated: 18/10/2016
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows malicious users to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified.

Vulnerable Product Search on Vulmon Subscribe to Product

sendmail sendmail 8.12.0

sendmail sendmail 8.12.1

sendmail sendmail 8.12.2

sendmail sendmail 8.12.3

sendmail sendmail 8.12.4

sendmail sendmail 8.12.5

sendmail sendmail 8.12.6

netbsd netbsd 1.5

netbsd netbsd 1.5.1

netbsd netbsd 1.5.2

netbsd netbsd 1.5.3

netbsd netbsd 1.6

Exploits

source: wwwsecurityfocuscom/bid/5845/info Sendmail is a freely available, open source mail transport agent It is maintained and distributed by the Sendmail Consortium Sendmail is available for the Unix and Linux operating systems smrsh is designed to prevent the execution of commands outside of the restricted environment However, whe ...