CyberSec.Space Logo
Back to CVE Browser

CVE-2004-1993

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0530%
EPSS Percentile42.17th
PublishedMay 4, 2004
Last ModifiedApr 16, 2026

Vulnerability Description

The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.

Affected Platforms (CPE)

πŸ“¦
Omail

Omail Webmail

= 0.97.3
πŸ“¦
Omail

Omail Webmail

= 0.98.3
πŸ“¦
Omail

Omail Webmail

= 0.98.5

References & Advisories

Related Vulnerabilities