.. / CVE-2014-1203

Exploit for Eyou E-Mail <3.6 - Remote Code Execution (CVE-2014-1203)

Description:

Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to admin/domain/ip_login_set/d_ip_login_get.php via the get_login_ip_config_file function.

Nuclei Template

View the template here CVE-2014-1203.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2014/CVE-2014-1203.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
http://seclists.org/fulldisclosure/2014/Jan/32
https://nvd.nist.gov/vuln/detail/CVE-2014-1203
https://github.com/ARPSyndicate/kenzer-templates
https://mp.weixin.qq.com/s/wH5luLISE_G381W2ssv93g