Required CVE Record Information
Description
An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute remote code on the target server. The user has to be authenticated before interacting with this page.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 5 Total
- https://www.spamtitan.com/ x_transferred
- https://github.com/felmoltor x_transferred
- https://twitter.com/felmoltor x_transferred
- https://sensepost.com/blog/2020/clash-of-the-spamtitan/ x_transferred
- http://packetstormsecurity.com/files/159218/SpamTitan-7.07-Remote-Code-Execution.html x_transferred