CVE-2001-0901
Hypermail allows remote attackers to execute arbitrary commands on a server supporting SSI via an attachment with a .shtml extension, which is archived on the server and can then be executed by requesting the URL for the attachment.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Hypermail allows remote attackers to execute arbitrary commands on a server supporting SSI via an attachment with a .shtml extension, which is archived on the server and can then be executed by requesting the URL for the attachment.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.63% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- hypermail development/hypermail
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=100626603407639&w=2Third Party Advisory
- http://www.hypermail.org/dist/hypermail-2.1.4.tar.gzBroken Link, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7576Third Party Advisory, VDB Entry
- http://marc.info/?l=bugtraq&m=100626603407639&w=2Third Party Advisory
- http://www.hypermail.org/dist/hypermail-2.1.4.tar.gzBroken Link, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7576Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.