10
CVSSv2

CVE-2007-2173

Published: 24/04/2007 Updated: 29/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP prior to 4.0.6-r2, and 4.1.x prior to 4.1.2-r1, on Gentoo Linux allows remote malicious users to execute arbitrary commands via the XMAILDIR variable, related to the LOGINRUN variable.

Vulnerable Product Search on Vulmon Subscribe to Product

double_precision_incorporated courier-imap 4.0.0

double_precision_incorporated courier-imap 4.0.1

double_precision_incorporated courier-imap 4.1.0

double_precision_incorporated courier-imap 4.1.1

double_precision_incorporated courier-imap 4.0.2

double_precision_incorporated courier-imap 4.0.3

double_precision_incorporated courier-imap 4.0.4

double_precision_incorporated courier-imap 4.0.5