ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-28007”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-28007
Published
2021-05-06
CVSS:
7.8
ShadowTrackr CVSS:
6.4
Summary:
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the log directory (owned by a non-root user), a symlink or hard link attack allows overwriting critical root-owned files anywhere on the filesystem.