module
Hastymail 2.1.1 RC1 Command Injection
Disclosed | Created |
---|---|
2011-11-22 | 2018-05-30 |
Disclosed
2011-11-22
Created
2018-05-30
Description
This module exploits a command injection vulnerability found in Hastymail
2.1.1 RC1 due to the insecure usage of the call_user_func_array() function on
the "lib/ajax_functions.php" script. Authentication is required on Hastymail
in order to exploit the vulnerability. The module has been successfully tested
on Hastymail 2.1.1 RC1 over Ubuntu 10.04.
2.1.1 RC1 due to the insecure usage of the call_user_func_array() function on
the "lib/ajax_functions.php" script. Authentication is required on Hastymail
in order to exploit the vulnerability. The module has been successfully tested
on Hastymail 2.1.1 RC1 over Ubuntu 10.04.
Authors
Bruno Teixeira
juan vazquez juan.vazquez@metasploit.com
juan vazquez juan.vazquez@metasploit.com
Platform
Unix
Architectures
cmd
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.