sendmessage.cgi in W3Mail 1.0.2, and possibly other CGI programs, allows remote attackers to execute arbitrary commands via shell metacharacters in any field of the Compose Message page.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| W3mail | Spencer_miles | 1.0.2 (including) | 1.0.2 (including) |