Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharacters in the Reply-To header.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/7527 | mailing list exploit vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/502 | vdb entry |