Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.
References
Link | Resource |
---|---|
https://github.com/outflanknl/Exploits/blob/master/harakiri-CVE-2016-1000282.py | Exploit Patch Third Party Advisory |
Configurations
Information
Published : 2019-02-05 09:29
Updated : 2019-02-06 05:11
NVD link : CVE-2016-1000282
Mitre link : CVE-2016-1000282
JSON object : View
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Products Affected
haraka_project
- haraka