CVE-2007-4560
clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the "recipient field of sendmail."
- Affected products
- Clamav
- Clam Anti-virus Clamav
- ≤ 0.91.1
- Fix
- Available
- CVSS 2.0
- 7.6 HIGH
- EPSS
- 83.5% (100th percentile)
- Weakness
- CWE-78
- NVD status
- Modified
- Published
- 2007-08-28
CVE-2007-4560 at NVD
15 known exploits for CVE-2007-4560
Proof-of-concept code and exploit modules indexed by Sploitus
ClamAV-Milter-Sendmail-0.91.2-Remote-Code-Execution
sendmail-clamav-exploit-CVE-2007-4560
Exploit for OS Command Injection in Clam_Anti-Virus Clamav
ClamAV Milter - Blackhole-Mode Remote Code Execution (Metasploit)
ClamAV Milter Blackhole-Mode Remote Code Execution
ClamAV Milter Blackhole-Mode Remote Code Execution
Sendmail with clamav-milter < 0.91.2 - Remote Command Execution
ClamAV milter popen command injection
ClamAV milter popen command injection
ClamAV milter popen command injection
ClamAV milter popen command injection
DSquare Exploit Pack: D2SEC_CLAMAV
ClamAV Milter 0.92.2 - Blackhole-Mode (Sendmail) Code Execution (Metasploit)
ClamAV Milter 0.92.2 - Blackhole-Mode (Sendmail) Code Execution (Metasploit)
ClamAV Milter <= 0.92.2 Blackhole-Mode (sendmail) Code Execution