Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2016-9920

Description

steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.

POC

Reference

- https://blog.ripstech.com/2016/roundcube-command-execution-via-email/

Github

- https://github.com/ARPSyndicate/cve-scores

- https://github.com/ARPSyndicate/cvemon

- https://github.com/CVEDB/awesome-cve-repo

- https://github.com/CVEDB/top

- https://github.com/GhostTroops/TOP

- https://github.com/NCSU-DANCE-Research-Group/CDL

- https://github.com/anquanscan/sec-tools

- https://github.com/fkie-cad/nvd-json-data-feeds

- https://github.com/hktalent/TOP

- https://github.com/t0kx/exploit-CVE-2016-9920