Mail2000 Vulnerability Allows Arbitrary System Command Execution
CVE-2024-5400
What is CVE-2024-5400?
A vulnerability exists in Openfind Mail2000 where improper filtering of parameters in certain CGI scripts allows an attacker with standard access to execute arbitrary system commands on the affected server. This flaw poses significant risks as it can lead to unauthorized control over the server environment, enabling potential data breaches and further system compromise.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mail2000 V8.0 earlier
News Articles
CVE-2024-5400 : OPENFIND MAIL2000 8.0 CGI OS COMMAND INJECTION - Cloud WAF
CVE-2024-5400 : Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.
References
CVSS V3.1
Timeline
- ๐ฐ
First article discovered by prophaze.com
Vulnerability published
Vulnerability Reserved
