HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure configurations. Attackers can exploit these flaws to access unauthorized functionality via a crafted URL.
Solution:
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://www.twcert.org.tw/tw/cp-132-3535-e40ec-1.html | third party advisory |
https://gist.github.com/tonykuo76/7d41c414f23ef1e47c97f7b97e1b33b0 | third party advisory |
https://www.chtsecurity.com/news/19400b04-ea92-4eaa-afa7-2449fd9b2e0b | third party advisory |