Hypermail allows remote attackers to execute arbitrary commands on a server supporting SSI via an attachment with a .shtml extension, which is archived on the server and can then be executed by requesting the URL for the attachment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Hypermail | Hypermail_development | * | * |