CVE-2014-1203
23Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 16%
exploitation probability
16%top 3% of all CVEs
observed exploitation
nono source reports it
The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to admin/domain/ip_login_set/d_ip_login_get.php.
Affected products
n/a · n/a