go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Openfind Mail2000 - OS Command Injection

TVN ID TVN-202405004
CVE ID CVE-2024-5400
CVSS 8.8 (High)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products Mail2000 V8.0 before Patch 34
Description Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.
Solution Update Mail2000 V8.0 to Patch 34 or later version.
Credit Openfind tech team(Openfind Information Technology, INC.)
Public Date 2024-05-27
Top