CVE-2020-7247
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists because of an incorrect return value upon failure of input validation.
- Openbsd Opensmtpd
- = 6.6
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 99.0% (100th percentile)
- Weakness
- CWE-755, CWE-78
- NVD status
- Analyzed
- Published
- 2020-01-29
CVE-2020-7247 at NVD
36 known exploits for CVE-2020-7247
Proof-of-concept code and exploit modules indexed by Sploitus
cve-2020-7247
OpenSMTPD-CVE-2020-7247-
CVE-2020-7247
cve-2020-7247-exploit
local-exploits
CVE-2020-7247-reproducer
CVE-2020-7247
CVE-2020-7247-exploit
CVE-2020-7247
CVE-2020-7247-POC
Exploit for OS Command Injection in Openbsd Opensmtpd
Exploit for CVE-2002-0526
Exploit for Improper Handling of Exceptional Conditions in Openbsd Opensmtpd
OpenBSD OpenSMTPD 6.6 Remote Code Execution Exploit
OpenBSD OpenSMTPD 6.6 Remote Code Execution
Exploit for Improper Handling of Exceptional Conditions in Openbsd Opensmtpd
Exploit for Improper Handling of Exceptional Conditions in Openbsd Opensmtpd
Exploit for Improper Handling of Exceptional Conditions in Openbsd Opensmtpd
OpenSMTPD 6.6.1 - Local Privilege Escalation Exploit
OpenSMTPD 6.4.0 6.6.1 - Local Privilege Escalation + Remote Code Execution
OpenSMTPD 6.4.0 < 6.6.1 - Local Privilege Escalation + Remote Code Execution
OpenSMTPD 6.6.1 Local Privilege Escalation
OpenSMTPD - MAIL FROM Remote Code Execution Exploit
OpenSMTPD - MAIL FROM Remote Code Execution (Metasploit)
OpenSMTPD MAIL FROM command injection
OpenSMTPD MAIL FROM command injection
OpenSMTPD MAIL FROM command injection
OpenSMTPD MAIL FROM Remote Code Execution
OpenSMTPD 6.6.2 - Remote Code Execution Exploit
OpenSMTPD 6.6.2 - Remote Code Execution
OpenSMTPD 6.6.1 - Remote Code Execution
OpenSMTPD 6.6.2 Remote Code Execution
Exploit for Improper Handling of Exceptional Conditions in Openbsd Opensmtpd
OpenBSD OpenSMTPD Privilege Escalation / Code Execution Vulnerabilities
OpenBSD OpenSMTPD Privilege Escalation / Code Execution
OpenSMTPD MAIL FROM Remote Code Execution