Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.
Metrics
Affected Vendors & Products
Fixes
Solution
Update Mail2000 V7.0 to Patch 124 or later version. Update Mail2000 V8.0 to Patch 31 or later version
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://www.twcert.org.tw/tw/cp-132-7817-6ce29-1.html |
![]() ![]() ![]() |
History
Sun, 13 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|

Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-01T21:11:12.667Z
Reserved: 2024-05-27T03:06:02.716Z
Link: CVE-2024-5399

Updated: 2024-08-01T21:11:12.667Z

Status : Awaiting Analysis
Published: 2024-05-27T04:15:09.300
Modified: 2024-11-21T09:47:34.720
Link: CVE-2024-5399

No data.

Updated: 2025-07-12T22:44:57Z