Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
email_in.pl in Bugzilla 2.23.4 through 3.0.0 allows remote attackers to execute arbitrary commands via the -f (From address) option to the Email::Send::Sendmail function, probably involving shell metacharacters.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Bugzilla 'email_in.pl'多个远程漏洞
Vulnerability Description
Bugzilla 2.23.4 版本至3.0.0版本的email_in.pl允许远程攻击者可以借助对Email::Send::Sendmail函数的-f (From address) 选项,可能包含外壳元字符,执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A