Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
E-Mail Security Virtual Appliance learn-msg.cgi Command Injection
Vulnerability Description
The E-Mail Security Virtual Appliance (ESVA) (tested on version ESVA_2057) contains an unauthenticated command injection vulnerability in the learn-msg.cgi script. The CGI handler fails to sanitize user-supplied input passed via the id parameter, allowing attackers to inject arbitrary shell commands. Exploitation requires no authentication and results in full command execution on the underlying system.
CVSS Information
N/A
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
ESVA-Project E-Mail Security Virtual Appliance 安全漏洞
Vulnerability Description
ESVA-Project E-Mail Security Virtual Appliance是ESVA-Project公司的一款电子邮件安全虚拟设备。 E-Mail Security Virtual Appliance ESVA_2057版本存在安全漏洞,该漏洞源于learn-msg.cgi脚本未清理用户输入,可能导致命令注入。
CVSS Information
N/A
Vulnerability Type
N/A