PineApp Mail-SeCure ldapsyncnow.php shell_command Command Execution

Strike ID:
E13-1wl01
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
4
Year:
2013

Description

This strike exploits an arbitrary code execution vulnerability in PineApp Mail-SeCure. A specially crafted HTTP request can be sent to ldapsyncnow.php to execute arbitrary commands with root privileges.

References