CVE-2019-6800
05.06.2019, 19:29
In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. An attacker with a privileged network position is trivially able to inject arbitrary commands.
Vendor | Product | Version |
---|---|---|
titanhq | spamtitan | 7.00 ≤ 𝑥 ≤ 7.03 |
𝑥
= Vulnerable software versions