vendor:
eXtremail
by:
mu-b
N/A
CVSS
HIGH
Remote Code Execution
CWE
Product Name: eXtremail
Affected Version From: 2.1.2000
Affected Version To: 2.1.2001
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2007
extremail-v8.pl
This Perl script exploits a remote code execution vulnerability in eXtremail <=2.1.1. It sends a payload to the target server, causing it to execute arbitrary code. The payload is sent in multiple iterations, increasing the chances of successful exploitation.
Mitigation:
Upgrade to a patched version of eXtremail.