Vulnerability Details CVE-2024-5400
Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.018
EPSS Ranking 82.9%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2024-5400
-
cpe:2.3:a:openfind:mail2000:6.0
-
cpe:2.3:a:openfind:mail2000:7.0
-
cpe:2.3:a:openfind:mail2000:8.0