Vulnerabilities > CVE-1999-0095 - Unspecified vulnerability in Eric Allman Sendmail 5.58

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
eric-allman
critical
nessus
exploit available

Summary

The debug command in Sendmail is enabled, allowing attackers to execute commands as root.

Vulnerable Configurations

Part Description Count
Application
Eric_Allman
1

Exploit-Db

descriptionBerkeley Sendmail 5.58 DEBUG Vulnerability. CVE-1999-0095. Remote exploit for linux platform
idEDB-ID:19028
last seen2016-02-02
modified1988-08-01
published1988-08-01
reporteranonymous
sourcehttps://www.exploit-db.com/download/19028/
titleBerkeley Sendmail 5.58 DEBUG Vulnerability

Nessus

NASL familySMTP problems
NASL idSENDMAIL_DEBUG.NASL
descriptionYour MTA accepts the DEBUG or WIZ command. It may be an old version of Sendmail. This command is dangerous as it allows remote users to execute arbitrary commands as root without the need to log in.
last seen2020-06-01
modified2020-06-02
plugin id10247
published1999-08-22
reporterThis script is Copyright (C) 1999-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/10247
titleSendmail DEBUG/WIZ Remote Command Execution