The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2005-05-10T04:00:00
Updated: 2024-08-08T01:07:49.164Z
Reserved: 2005-05-04T00:00:00
Link: CVE-2004-1993

No data.

Status : Modified
Published: 2004-05-04T04:00:00.000
Modified: 2024-11-20T23:52:14.690
Link: CVE-2004-1993

No data.