sendmessage.cgi in W3Mail 1.0.2, and possibly other CGI programs, allows remote attackers to execute arbitrary commands via shell metacharacters in any field of the 'Compose Message' page.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/3673 | vdb entry vendor advisory |
http://www.securityfocus.com/archive/1/218921 | patch vendor advisory mailing list exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7230 | vdb entry |
http://www.w3mail.org/ChangeLog |