go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

HGiga MailSherlock - Arbitrary File Download

TVN ID TVN-202011003
CVE ID CVE-2020-25850
CVSS 8.1(High)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products MailSherlock MSR45/SSR45
Module: iSherlock-user-4.5 < 117
Description The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.
Solution Update MailSherlock MSR45/SSR45 Module to iSherlock-user-4.5-117.i386.rpm
Credit Robin Tung (CHT)、Dio Lin (CHT)
Public Date 2020-12-30
Top