MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter.
Link | Tags |
---|---|
http://www.endymion.com/products/mailman/history.htm | |
http://www.securityfocus.com/bid/2063 | patch vendor advisory vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2000-12/0057.html | patch vendor advisory mailing list exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/5649 | vdb entry |