Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2019-10149

KEV EPSS 93.92% · P100
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-10149

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Exim 操作系统命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Exim是一个运行于Unix系统中的开源消息传送代理(MTA),它主要负责邮件的路由、转发和投递。 Exim 4.87版本至4.91版本中存在操作系统命令注入漏洞。该漏洞源于网络系统或产品未对输入的数据进行正确的验证。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
eximexim 4.92 -

II. Public POCs for CVE-2019-10149

#POC DescriptionSource LinkShenlong Link
1quick fix for CVE-2019-10149, works on Debian\Ubuntu\Centoshttps://github.com/bananaphones/exim-rce-quickfixPOC Details
2simple python socket connection to test if exim is vulnerable to CVE-2019-10149. The payload simply touch a file in /tmp/eximrce.https://github.com/cowbe0x004/eximrce-CVE-2019-10149POC Details
3PoC for CVE-2019-10149, this vulnerability could be xploited betwen 4-87 to 4.91 version of Exim server.https://github.com/MNEMO-CERT/PoC--CVE-2019-10149_EximPOC Details
4Simple Bash shell quick fix CVE-2019-10149https://github.com/aishee/CVE-2019-10149-quickPOC Details
5CVE-2019-10149 privilege escalationhttps://github.com/AzizMea/CVE-2019-10149-privilege-escalationPOC Details
6Exim Honey Pot for CVE-2019-10149 exploit attempts.https://github.com/Brets0150/StickyEximPOC Details
7CVE-2019-10149https://github.com/Chris-dev1/exim.expPOC Details
8Instructions for installing a vulnerable version of Exim and its expluatationhttps://github.com/darsigovrustam/CVE-2019-10149POC Details
9CVE-2019-10149 : A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.https://github.com/Diefunction/CVE-2019-10149POC Details
10SNP Assignment on a Linux vulnerabilityhttps://github.com/Dilshan-Eranda/CVE-2019-10149POC Details
11Data Collection Related to Exim CVE-2019-10149https://github.com/cloudflare/exim-cve-2019-10149-dataPOC Details
12Exploit for CVE-2019-10149https://github.com/Stick-U235/CVE-2019-10149-ExploitPOC Details
13Nonehttps://github.com/rahmadsandy/EXIM-4.87-CVE-2019-10149POC Details
14CVE-2019-10149https://github.com/hyim0810/CVE-2019-10149POC Details
15test POC for CVE-2019-10149https://github.com/qlusec/CVE-2019-10149POC Details
16Remote Command Execution into shell from a vulnerable exim service.https://github.com/uyerr/PoC_CVE-2019-10149--rcePOC Details
17PoC for exploitation of vulnerability CVE-2019-10149https://github.com/VoyagerOnne/Exim-CVE-2019-10149POC Details
18Cr. Exim 4.87 - 4.91 - Local Privilege Escalation https://github.com/Cheryanika/CVE-2019-10149---Exim4---RCEPOC Details
19Nonehttps://github.com/CybersRMUTL/CVE-2019-10149-Exim4-RCEPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-10149

登录查看更多情报信息。

Vendor Advisories for CVE-2019-10149 (4)

Exploits & Public PoCs for CVE-2019-10149 (3)

Mailing List Discussions for CVE-2019-10149 (8)

Other References for CVE-2019-10149 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2019-10149

No comments yet


Leave a comment