5
CVSSv2

CVE-2007-4538

Published: 27/08/2007 Updated: 15/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

email_in.pl in Bugzilla 2.23.4 up to and including 3.0.0 allows remote malicious users to execute arbitrary commands via the -f (From address) option to the Email::Send::Sendmail function, probably involving shell metacharacters.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla bugzilla 2.6

mozilla bugzilla 2.8

mozilla bugzilla 2.23.4

mozilla bugzilla 2.4

mozilla bugzilla 2.9

mozilla bugzilla 3.0.0