HGiga iSherlock
cpe:2.3:a:hgiga:ssr45_isherlock-user:*:*:*:*:*:*:*
- < 236
A command injection vulnerability has been identified in the web service of HGiga's iSherlock, versions 4.5 and 5.5 (including MailSherlock, SpamSherlock, and AuditSherlock). This vulnerability allows unauthenticated remote attackers to inject and execute arbitrary operating system commands on the server.
Exploitation of this vulnerability allows for arbitrary OS command execution on the server.
Users of iSherlock 4.5 should update the iSherlock-user-4.5 package to version 236 or later. Users of iSherlock 5.5 should update the iSherlock-user-5.5 package to version 236 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.