ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-28008”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-28008
Published
2021-05-06
CVSS:
7.8
ShadowTrackr CVSS:
6.4
Summary:
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the spool directory (owned by a non-root user), an attacker can write to a /var/spool/exim4/input spool header file, in which a crafted recipient address can indirectly lead to command execution.