CVE-2020-35851

HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and execute arbitrary commands of the system.
References
Link Resource
https://www.twcert.org.tw/en/cp-139-4264-f10f4-2.html Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hgiga:msr45_isherlock-user:*:*:*:*:*:*:*:*
cpe:2.3:a:hgiga:ssr45_isherlock-user:*:*:*:*:*:*:*:*

Information

Published : 2020-12-31 00:15

Updated : 2021-01-07 13:32


NVD link : CVE-2020-35851

Mitre link : CVE-2020-35851


JSON object : View

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Advertisement

dedicated server usa

Products Affected

hgiga

  • ssr45_isherlock-user
  • msr45_isherlock-user