Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Thijs Dalhuijsen

#23202de 53,639
10CVSS total
Vulnerabilidades · 1
PT-2004-2889
10
2004-05-04
Omail · @Mail Webmail · CVE-2004-1993
**Name of the Vulnerable Software and Affected Versions** omail webmail version 0.98.5 **Description** The issue concerns an incomplete patch to the `checklogin` function in `omail.pl`, allowing remote attackers to execute arbitrary commands. This can be achieved by using shell metacharacters, such as backticks, in the `password` variable. **Recommendations** For omail webmail version 0.98.5, consider disabling the `checklogin` function until a complete patch is available. Restrict access to the `omail.pl` script to minimize the risk of exploitation. Avoid using backticks or other shell metacharacters in the `password` variable until the issue is resolved.