Vulnerabilities > CVE-2001-0021 - Unspecified vulnerability in Endymion Mailman Webmail

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
endymion
critical
nessus
exploit available

Summary

MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter.

Exploit-Db

descriptionEndymion MailMan 3.0..x Remote Arbitrary Command Execution Vulnerability. CVE-2001-0021. Remote exploit for unix platform
idEDB-ID:20469
last seen2016-02-02
modified2000-12-06
published2000-12-06
reporterSecure Reality Advisories
sourcehttps://www.exploit-db.com/download/20469/
titleEndymion MailMan 3.0.x - Remote Arbitrary Command Execution Vulnerability

Nessus

NASL familyCGI abuses
NASL idMAILMAN_WEBMAIL.NASL
descriptionThe version of MailMan Webmail on the remote web server has an arbitrary command execution vulnerability. Input to the
last seen2020-06-01
modified2020-06-02
plugin id10566
published2000-12-06
reporterThis script is Copyright (C) 2000-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10566
titleMailMan Webmail mmstdod.cgi Arbitrary Command Execution