MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.
References
Configurations
History
21 Nov 2024, 08:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/176273/MajorDoMo-Remote-Code-Execution.html - | |
References | () http://packetstormsecurity.com/files/176669/MajorDoMo-Command-Injection.html - | |
References | () http://seclists.org/fulldisclosure/2023/Dec/19 - | |
References | () https://github.com/sergejey/majordomo/commit/0662e5ebfb133445ff6154b69c61019357092178 - Patch | |
References | () https://github.com/sergejey/majordomo/commit/3ec3ffb863ea3c2661ab27d398776c551f4daaac - Patch |
22 Jan 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
20 Dec 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-77 | |
First Time |
Mjdm
Mjdm majordomo |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CPE | cpe:2.3:a:mjdm:majordomo:*:*:*:*:*:*:*:* | |
References |
|
|
References | () https://github.com/sergejey/majordomo/commit/3ec3ffb863ea3c2661ab27d398776c551f4daaac - Patch | |
References | () https://github.com/sergejey/majordomo/commit/0662e5ebfb133445ff6154b69c61019357092178 - Patch |
15 Dec 2023, 20:09
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-15 17:15
Updated : 2024-11-21 08:37
NVD link : CVE-2023-50917
Mitre link : CVE-2023-50917
CVE.ORG link : CVE-2023-50917
JSON object : View
Products Affected
mjdm
- majordomo
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')