CVE-2020-4688

CVSS v3 Score
5.9
Medium
CVSS v2 Score
7.2
High

Vulnerability Description

IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability. IBM X-Force ID: 186700.

CVSS:5.9(Medium)

In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials...

CWE-772020
CVSS:5.9(Medium)

An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands int...

CWE-772020
CVSS:5.9(Medium)

In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.

CWE-772021
CVSS:5.9(Medium)

Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially...

CWE-772021
CVSS:5.9(Medium)

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.

CWE-772024
CVSS:5.9(Medium)

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.

CWE-772024