Vulnerabilities > CVE-1999-0145 - Unspecified vulnerability in Eric Allman Sendmail

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
eric-allman
nessus

Summary

Sendmail WIZ command enabled, allowing root access.

Vulnerable Configurations

Part Description Count
Application
Eric_Allman
1

Nessus

NASL familySMTP problems
NASL idSENDMAIL_DEBUG.NASL
descriptionYour MTA accepts the DEBUG or WIZ command. It may be an old version of Sendmail. This command is dangerous as it allows remote users to execute arbitrary commands as root without the need to log in.
last seen2020-06-01
modified2020-06-02
plugin id10247
published1999-08-22
reporterThis script is Copyright (C) 1999-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/10247
titleSendmail DEBUG/WIZ Remote Command Execution