CVE-2014-1203
Eyou E-Mail <3.6 - Remote Code Execution
Record summary
CVE-2014-1203 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to admin/domain/ip_login_set/d_ip_login_get.php.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALEyou E-Mail <3.6 - Remote Code ExecutionCVSS 9.8
Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to admin/domain/ip_login_set/d_ip_login_get.php via the get_login_ip_config_file function.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
Remediation
Upgrade to a patched version of Eyou E-Mail <3.6 or apply the necessary security patches.
Source: ProjectDiscovery