Description
Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.
No analysis available yet.
Remediation
Vendor Solution
Update Mail2000 V7.0 to Patch 124 or later version. Update Mail2000 V8.0 to Patch 31 or later version
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46622 | Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the remote server. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7817-6ce29-1.html |
|
History
Mon, 26 Jan 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:openfind:mail2000:7.0:*:*:*:*:*:*:* cpe:2.3:a:openfind:mail2000:8.0:*:*:*:*:*:*:* |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-01T21:11:12.667Z
Reserved: 2024-05-27T03:06:02.716Z
Link: CVE-2024-5399
Updated: 2024-08-01T21:11:12.667Z
Status : Analyzed
Published: 2024-05-27T04:15:09.300
Modified: 2026-01-26T13:49:40.630
Link: CVE-2024-5399
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:44:57Z
Weaknesses
EUVD