vendor:
Listmail
by:
P.M.Systems
7,5
CVSS
HIGH
Insecure open call
78
CWE
Product Name: Listmail
Affected Version From: Listmail v112
Affected Version To: Listmail v112
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2002
Listmail v112 by P.M.Systems / PoC Exploit
Listmail is a powerful, hands-free mailing list manager which is exploitable due to an insecure open call. This exploit will attempt to bind a shell at port 60179/fido by using inetd. Code to spawn an xterm is as always included.
Mitigation:
Ensure that the open call is secure and that the code is not vulnerable to any malicious attacks.