CVE-2018-11616: OS Command Injection
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.9.115. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI handlers. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5543.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11616?
CVE-2018-11616 is a vulnerability that allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.9.115.
How severe is CVE-2018-11616?
CVE-2018-11616 has a severity rating of 8.8 which is considered high.
How does the vulnerability in Tencent Foxmail 7.2.9.115 occur?
The vulnerability in Tencent Foxmail 7.2.9.115 occurs when a user visits a malicious page or opens a malicious file.
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for this vulnerability is 78.
Where can I find more information about CVE-2018-11616?
You can find more information about CVE-2018-11616 at the following reference: https://zerodayinitiative.com/advisories/ZDI-18-584