The checklogin function in omail.pl for omail webmail 0.98.4 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) password, (2) domainname, or (3) username.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Omail_webmail | Omail | 0.97.3 (including) | 0.97.3 (including) |
Omail_webmail | Omail | 0.98.4 (including) | 0.98.4 (including) |