RSS   Vulnerabilities for 'Omail webmail'   RSS

2004-05-04
 
CVE-2004-1993

 

 
The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.

 
2003-08-19
 
CVE-2003-1202

 

 
The checklogin function in omail.pl for omail webmail 0.98.4 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) password, (2) domainname, or (3) username.

 


Copyright 2024, cxsecurity.com

 

Back to Top