Unrated severityNVD Advisory· Published Mar 19, 2006· Updated Apr 16, 2026
CVE-2006-1251
CVE-2006-1251
Description
Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- marc.merlins.org/linux/exim/files/sa-exim-cvs/Changelog.htmlnvdPatch
- www.securityfocus.com/bid/17110nvdPatch
- secunia.com/advisories/19225nvdVendor Advisory
- www.vupen.com/english/advisories/2006/0941nvdVendor Advisory
- bugs.debian.org/cgi-bin/bugreport.cginvd
- exchange.xforce.ibmcloud.com/vulnerabilities/25286nvd
News mentions
0No linked articles in our index yet.