OpenSMTPD 6.6.1p1, vulnerable to CVE-2020-7247: smtp_mailaddr accepts a local part with shell metacharacters when the domain is empty, and the mail delivery agent then runs the sender address in a shell command line as root.
Not startedDockercommit c8353d5x86_64 · aarch64Secret
Exploit CVE-2020-7247 through the SMTP dialogue to run commands as root on the mail server.
The brief for this lab lives in its repository.