Back to Database
Status published
Critical
CVE-2001-0021
MailMan Webmail 3.0.25 and earlier allows remote attackers to execute...
Vulnerability Description
MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2001-0021
Credits & Attribution
No credits recorded in the NVD database.
References
More from endymion
View All →CVE-2002-0418
Directory traversal vulnerability in the com.endymion.sake.servlet.mail.MailServlet servlet for Endymion SakeMail...
Medium
5
CVE-2002-0417
Directory traversal vulnerability in Endymion MailMan before 3.1 allows remote...
Medium
5
CVE-1999-0850
The default permissions for Endymion MailMan allow local users to...
Low
3.6
Affected Vendor
endymion
View all reports →Affected Software
mailman webmail
Vulnerable Versions:
3.0, 3.0.1, 3.0.10, 3.0.11, 3.0.12, 3.0.13, 3.0.14, 3.0.15, 3.0.16, 3.0.18, 3.0.19, 3.0.20, 3.0.21, 3.0.22, 3.0.23, 3.0.24, 3.0.25
Timeline
Official Publish:
May 7th, 2001
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.