Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46623 | Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands on the remote server. |
Fixes
Solution
Update Mail2000 V8.0 to Patch 34 or later version.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7819-9661a-1.html |
|
History
Mon, 26 Jan 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:openfind:mail2000:6.0:*:*:*:*:*:*:* cpe:2.3:a:openfind:mail2000:7.0:*:*:*:*:*:*:* cpe:2.3:a:openfind:mail2000:8.0:*:*:*:*:*:*:* |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-01T21:11:12.528Z
Reserved: 2024-05-27T03:06:04.074Z
Link: CVE-2024-5400
Updated: 2024-08-01T21:11:12.528Z
Status : Analyzed
Published: 2024-05-27T06:15:10.620
Modified: 2026-01-26T13:42:45.840
Link: CVE-2024-5400
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:09:57Z
Weaknesses
EUVD