CVE-2007-4538

email_in.pl in Bugzilla 2.23.4 through 3.0.0 allows remote attackers to execute arbitrary commands via the -f (From address) option to the Email::Send::Sendmail function, probably involving shell metacharacters.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:bugzilla:2.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.23.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.9:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.0.0:*:*:*:*:*:*:*

Information

Published : 2007-08-27 14:17

Updated : 2018-10-15 14:35


NVD link : CVE-2007-4538

Mitre link : CVE-2007-4538


JSON object : View

Advertisement

dedicated server usa

Products Affected

mozilla

  • bugzilla