go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

HGiga MailSherlock - Command Injection

TVN ID TVN-202011002
CVE ID CVE-2020-35851
CVSS 8.1(High)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products MailSherlock MSR45/SSR45
Module: iSherlock-user-4.5 < 115
Description HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and execute arbitrary commands of the system.
Solution Update MailSherlock MSR45/SSR45 Module to iSherlock-user-4.5-115.i386.rpm
Credit Robin Tung (CHT)、Dio Lin (CHT)
Public Date 2020-12-30
Top