CVE-2007-4560
HIGH 7.6EPSS 83.5%
clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the "recipient field of sendmail."
- CVSS v2.0
- 7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C - EPSS
- 83.54% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2007-08-28
- Updated
- 2024-08-07
Proof-of-concept exploits (3)
- 0x1sac/ClamAV-Milter-Sendmail-0.91.2-Remote-Code-Execution0★ · 2023-01-27
- Sic4rio/-Sendmail-with-clamav-milter-0.91.2---Remote-Command-Execution0★ · 2023-12-20
- Strikoder-Premium/sendmail-clamav-exploit-CVE-2007-4560
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/16924
- https://www.exploit-db.com/exploits/9913
- https://www.exploit-db.com/exploits/4761