LakeWeb Mail List CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.
Link | Tags |
---|---|
http://lakeweb.com/scripts/ | vendor advisory |
http://www.securityfocus.com/archive/1/11175 | mailing list exploit patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/1400 | vdb entry |