CVE-2023-50917

MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mjdm:majordomo:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:37

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/176273/MajorDoMo-Remote-Code-Execution.html - () http://packetstormsecurity.com/files/176273/MajorDoMo-Remote-Code-Execution.html -
References () http://packetstormsecurity.com/files/176669/MajorDoMo-Command-Injection.html - () http://packetstormsecurity.com/files/176669/MajorDoMo-Command-Injection.html -
References () http://seclists.org/fulldisclosure/2023/Dec/19 - () http://seclists.org/fulldisclosure/2023/Dec/19 -
References () https://github.com/sergejey/majordomo/commit/0662e5ebfb133445ff6154b69c61019357092178 - Patch () https://github.com/sergejey/majordomo/commit/0662e5ebfb133445ff6154b69c61019357092178 - Patch
References () https://github.com/sergejey/majordomo/commit/3ec3ffb863ea3c2661ab27d398776c551f4daaac - Patch () https://github.com/sergejey/majordomo/commit/3ec3ffb863ea3c2661ab27d398776c551f4daaac - Patch

22 Jan 2024, 17:15

Type Values Removed Values Added
References
  • () http://packetstormsecurity.com/files/176669/MajorDoMo-Command-Injection.html -

20 Dec 2023, 14:15

Type Values Removed Values Added
CWE CWE-77
First Time Mjdm
Mjdm majordomo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:mjdm:majordomo:*:*:*:*:*:*:*:*
References
  • () http://seclists.org/fulldisclosure/2023/Dec/19 -
  • () http://packetstormsecurity.com/files/176273/MajorDoMo-Remote-Code-Execution.html -
References () https://github.com/sergejey/majordomo/commit/3ec3ffb863ea3c2661ab27d398776c551f4daaac - () https://github.com/sergejey/majordomo/commit/3ec3ffb863ea3c2661ab27d398776c551f4daaac - Patch
References () https://github.com/sergejey/majordomo/commit/0662e5ebfb133445ff6154b69c61019357092178 - () https://github.com/sergejey/majordomo/commit/0662e5ebfb133445ff6154b69c61019357092178 - Patch

15 Dec 2023, 20:09

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-15 17:15

Updated : 2024-11-21 08:37


NVD link : CVE-2023-50917

Mitre link : CVE-2023-50917

CVE.ORG link : CVE-2023-50917


JSON object : View

Products Affected

mjdm

  • majordomo
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')