sendmessage.cgi in W3Mail 1.0.2, and possibly other CGI programs, allows remote attackers to execute arbitrary commands via shell metacharacters in any field of the Compose Message page.
Name | Vendor | Start Version | End Version |
---|---|---|---|
W3mail | Spencer_miles | 1.0.2 (including) | 1.0.2 (including) |