Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2010-1123

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Chip Salzenberg Deliver存在权限提升和拒绝服务漏洞。Chip Salzenberg Deliver没有正确的辅助具有创建文件权限的用户的锁文件,远程攻击者可以借助为任意 mailboxes创建锁文件,导致拒绝服务(封锁e-mail进入)。

AI Predicted 5.6 Difficulty: Easy EPSS 0.23% · P14
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2010-1123

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Chip Salzenberg Deliver does not properly associate a lockfile with the user who created the file, which allows local users to cause a denial of service (blockage of incoming e-mail) by creating lockfiles for arbitrary mailboxes.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Chip_Salzenberg Deliver本地权限提升和拒绝服务漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Chip Salzenberg Deliver存在权限提升和拒绝服务漏洞。Chip Salzenberg Deliver没有正确的辅助具有创建文件权限的用户的锁文件,远程攻击者可以借助为任意 mailboxes创建锁文件,导致拒绝服务(封锁e-mail进入)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2010-1123

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-1123

登录查看更多情报信息。

Vendor Advisories for CVE-2010-1123 (3)

Same Patch Batch · n/a · 2010-03-26 · 34 CVEs total

CVE-2010-1130 PHP session扩展件'session.c'权限许可和访问控制漏洞
CVE-2009-4750 Phppower Top Paidmailer 'home.php' PHP远程文件包含漏洞
CVE-2009-4751 Phppower Swinger Club Portal 'anzeiger/start.php' SQL注入漏洞
CVE-2009-4752 Phppower Swinger Club Portal 'anzeiger/start.php' PHP远程文件包含漏洞
CVE-2010-1125 Mozilla Firefox和SeaMonkey JavaScript信息泄露漏洞
CVE-2010-1126 Apple WebKit JavaScript信息泄露漏洞
CVE-2010-1127 Microsoft Internet Explorer 拒绝服务漏洞
CVE-2010-1128 PHP LCG不充分熵漏洞
CVE-2010-1129 PHP tempnam()函数safe_mode验证绕过安全限制漏洞
CVE-2009-4749 PHPLive! 'request.php'多个SQL注入漏洞
CVE-2009-4505 Alkacon OpenCMS OAMP Comments Module多个跨站脚本攻击漏洞
CVE-2010-0439 Chip Salzenberg Deliver权限提升和拒绝服务漏洞
CVE-2010-0731 GnuTLS X.509证书序列号解码绕过安全检查漏洞
CVE-2010-0740 OpenSSL 输入验证错误漏洞
CVE-2010-0988 Pulse CMS 多个PHP代码注入漏洞
CVE-2010-0989 Pulse CMS 'delete.php'目录遍历漏洞
CVE-2010-1124 IBM AIX bos.rte.libc设计错误漏洞
CVE-2010-1131 Apple Safari JavaScriptCore.dll 'object' 标签远程拒绝服务漏洞
CVE-2009-4748 WordPress My Category Order 插件 'parentID' 参数SQL 注入漏洞
CVE-2009-4747 Tecnick AIOCP 'cp_html2xhtmlbasic.php' 远程文件包含漏洞

Showing top 20 of 34 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-1123

No comments yet


Leave a comment