header-logo
Suggest Exploit
vendor:
SpamTitan Gateway
by:
Felipe Molina (@felmoltor)
8.8
CVSS
HIGH
Multiple Authenticated Remote Code Execution
20, 78, 79, 80
CWE
Product Name: SpamTitan Gateway
Affected Version From: 7.07
Affected Version To: 7.07
Patch Exists: YES
Related CWE: CVE-2020-11699, CVE-2020-11700, CVE-2020-11803, CVE-2020-11804
CPE: a:titanhq:spamtitan_gateway
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: FreeBSD
2020

SpamTitan 7.07 – Remote Code Execution (Authenticated)

Multiple authenticated remote code execution (RCE) vulnerabilities were found on the SpamTitan Gateway 7.07 and probably in pervious versions: CVE-2020-11699: Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute remote code on the target server. The user has to be authenticated before interacting with this page. CVE-2020-11700: Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker to retrieve the contents of arbitrary files. The user has to be authenticated before interacting with this page. CVE-2020-11803: Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lead to PHP code evaluatiom. The user has to be authenticated before interacting with this page. CVE-2020-11804: Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lead to PHP code evaluatiom. The user has to be authenticated before interacting with this page.

Mitigation:

Upgrade to the latest version of SpamTitan Gateway.
Source

Exploit-DB raw data: