CVE-2004-1993
CRITICAL
10.0
CVSS Severity Score
Vulnerability Description
The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.
Affected Platforms (CPE)
π¦
Omail
Omail Webmail
= 0.97.3π¦
Omail
Omail Webmail
= 0.98.3π¦
Omail
