The E-Mail Security Virtual Appliance (ESVA) (tested on version ESVA_2057) contains an unauthenticated command injection vulnerability in the learn-msg.cgi script. The CGI handler fails to sanitize user-supplied input passed via the id parameter, allowing attackers to inject arbitrary shell commands. Exploitation requires no authentication and results in full command execution on the underlying system.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Aug 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Esva Project
Esva Project esva |
|
Vendors & Products |
Esva Project
Esva Project esva |
Fri, 08 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 08 Aug 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The E-Mail Security Virtual Appliance (ESVA) (tested on version ESVA_2057) contains an unauthenticated command injection vulnerability in the learn-msg.cgi script. The CGI handler fails to sanitize user-supplied input passed via the id parameter, allowing attackers to inject arbitrary shell commands. Exploitation requires no authentication and results in full command execution on the underlying system. | |
Title | E-Mail Security Virtual Appliance learn-msg.cgi Command Injection | |
Weaknesses | CWE-78 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-08-08T18:11:08.292Z
Updated: 2025-08-08T18:54:01.060Z
Reserved: 2025-08-08T14:07:07.869Z
Link: CVE-2012-10046

Updated: 2025-08-08T18:53:51.144Z

Status : Awaiting Analysis
Published: 2025-08-08T19:15:34.597
Modified: 2025-08-08T20:30:18.180
Link: CVE-2012-10046

No data.