Family: CGI abuses --> Category: infos
Ingo Foldername Command Execution Vulnerability Vulnerability Scan
Vulnerability Scan Summary
Checks version number of Ingo
Detailed Explanation for this Vulnerability Test
The remote web server contains a PHP script that is affected by a
command execution vulnerability.
According to its version number, the instance of Ingo installed on the
remote host fails to properly sanitize mailbox destinations in filter
rules. By using a folder name beginning with '|' as a mailbox
destination, an authenticated remote attacker may be able to exploit
this issue to execute arbitrary code on the remote host, subject to
the permissions of the web server user id.
See also :
Upgrade to Ingo version H3 (1.1.2) or later.
Medium / CVSS Base Score : 4
Click HERE for more information and discussions on this network vulnerability scan.