The checklogin function in omail.pl for omail webmail 0.98.4 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) password, (2) domainname, or (3) username. Fixed in version 0.98.5. However, there is a report that version 0.98.5 is still affected by this vulnerability.
Publication date: Tue, 19 Aug 2003 09:00:00 +0000