ClamAV版本之前的版本0.91.2版本的clamav-milter,当在black hole mode中运行时,远程攻击者可以借助在某popen调用程序中的外壳元字符,且这些元字符涉及sendmail字段的获取",以执行任意指令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Exploit for CVE-2007-4560 (ClamAV Milter Sendmail 0.91.2 Remote Code Execution) | https://github.com/0x1sac/ClamAV-Milter-Sendmail-0.91.2-Remote-Code-Execution | POC Details |
| 2 | Python RCE exploit for Sendmail with ClamAV-Milter <0.91.2 (CVE-2007-4560). Remote root command injection via SMTP RCPT TO headers. | https://github.com/strikoder/sendmail-clamav-exploit-CVE-2007-4560 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2007-4557 | Novell GroupWise WebAccess 跨站脚本攻击漏洞 | |
| CVE-2007-4580 | Trustware BufferZone 缓冲区溢出漏洞 | |
| CVE-2007-4578 | Sophos Antivirus UPX文件解析拒绝服务漏洞 | |
| CVE-2007-4577 | Sophos Antivirus BZIP文件解析拒绝服务漏洞 | |
| CVE-2007-3846 | Subversion for Windows Remote 目录遍历漏洞 | |
| CVE-2007-4566 | SIDVault Simple_Bind函数多个远程栈溢出漏洞 | |
| CVE-2007-4565 | Fetchmail无效警告消息本地拒绝服务漏洞 | |
| CVE-2007-4564 | Hitachi Cosminexus Application Server 多个授权访问漏洞 | |
| CVE-2007-4563 | Hitachi Cosminexus Application Server 多个授权访问漏洞 | |
| CVE-2007-4562 | Hitachi DABroker拒绝服务漏洞 | |
| CVE-2007-4561 | Real Networks Helix服务器RTSP命令远程堆溢出漏洞 | |
| CVE-2007-4549 | ALPass Import Site Information 缓冲区溢出漏洞 | |
| CVE-2007-4556 | XWork AltSyntax功能OGNL命令注入漏洞 | |
| CVE-2007-4521 | Asterisk畸形MIME体远程拒绝服务漏洞 | |
| CVE-2006-7222 | Media Player Classic FLI文件处理远程缓冲区溢出漏洞 | |
| CVE-2007-4559 | Python tarfile 模块路径遍历漏洞 | |
| CVE-2007-4555 | Ipswitch WS_FTP 跨站脚本攻击漏洞 | |
| CVE-2007-4554 | TikiWiki tiki-remind_password.php文件跨站脚本漏洞 | |
| CVE-2007-4553 | Thomson ST SIP phone拒绝服务漏洞 | |
| CVE-2007-4552 | RETIRED: Arcadem Index.PHP SQL注入漏洞 |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet