7.5
CVSSv3

CVE-2019-6800

Published: 05/06/2019 Updated: 06/06/2019
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 756
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

In TitanHQ SpamTitan up to and including 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. An attacker with a privileged network position is trivially able to inject arbitrary commands.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

titanhq spamtitan