vendor:
Bash
by:
fattymcwopr
7,5
CVSS
HIGH
Shellshock
78
CWE
Product Name: Bash
Affected Version From: 4.2.x
Affected Version To: 4.2.48
Patch Exists: YES
Related CWE: 2014-6271
CPE: gnu.org/gnu/bash/
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Debian 7
2014
Shellshock SMTP Exploit
This exploit is used to execute arbitrary commands on a vulnerable SMTP server using the Shellshock vulnerability. The exploit is tested on Debian 7 (postfix smtp server w/procmail). The vulnerable version is 4.2.x < 4.2.48.
Mitigation:
The best way to mitigate the Shellshock vulnerability is to patch the vulnerable version of Bash. Additionally, system administrators should also consider disabling CGI scripts and other services that use Bash.