CVE-2001-0901
7.5
CVSS Score
High
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Link copied!
Description
Hypermail allows remote attackers to execute arbitrary commands on a server supporting SSI via an attachment with a .shtml extension, which is archived on the server and can then be executed by requesting the URL for the attachment.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
P
Availability
P
Affected Software Configurations
- a hypermail_development hypermail * * * * * * * *
Weaknesses (CWE)
- CWE-434
References & External Links
- http://marc.info/?l=bugtraq&m=100626603407639&w=2
- http://www.hypermail.org/dist/hypermail-2.1.4.tar.gz
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7576
- http://marc.info/?l=bugtraq&m=100626603407639&w=2
- http://www.hypermail.org/dist/hypermail-2.1.4.tar.gz
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7576
External Resources
CVE History Timeline
Jan 01, 2004 05:00
Initial Analysis
Oct 18, 2016 02:13
CVE Modified
Oct 10, 2017 01:29
CVE Modified
Jan 26, 2024 20:01
Modified Analysis
May 14, 2024 01:19
CVE Modified
Nov 20, 2024 23:36
CVE Modified