CVE-2004-1993 Information
Feb 14, 2021
cve
Description
The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete which allows remote attackers to execute arbitrary commands via shell metacharacters such as `\ (backticks) in the password.
Reference
http://marc.info/?l=bugtraq&m=108377215015515&w=2 http://secunia.com/advisories/9585 http://www.securityfocus.com/bid/10274 https://exchange.xforce.ibmcloud.com/vulnerabilities/12948
Share on: