VulnerabilityModified
CVE-2006-0845
Wright's Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs, including shell commands, by configuring the sendmail path to a malicious pathname.
MEDIUM 6.5EPSS 1.30%
Does this matter?
Lower severity and a low EPSS score (1.30%). Track it; it rarely justifies an emergency change on its own.
Description
Leif M. Wright's Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs, including shell commands, by configuring the sendmail path to a malicious pathname.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.30% probability · 69th percentile
- CISA KEV
- Not listed
- Affected
- leif m. wright/web blog
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/18923Vendor Advisory
- http://securityreason.com/securityalert/522
- http://www.evuln.com/vulns/82/summary.htmlVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24757
- http://secunia.com/advisories/18923Vendor Advisory
- http://securityreason.com/securityalert/522
- http://www.evuln.com/vulns/82/summary.htmlVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24757
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.