Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.
References
Link | Resource |
---|---|
https://github.com/outflanknl/Exploits/blob/master/harakiri-CVE-2016-1000282.py | Exploit Patch Third Party Advisory |
https://github.com/outflanknl/Exploits/blob/master/harakiri-CVE-2016-1000282.py | Exploit Patch Third Party Advisory |
Configurations
History
No history.
Information
Published : 2019-02-05 17:29
Updated : 2024-11-21 02:43
NVD link : CVE-2016-1000282
Mitre link : CVE-2016-1000282
CVE.ORG link : CVE-2016-1000282
JSON object : View
Products Affected
haraka_project
- haraka
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')