JamMail 1.8 - Jammail.pl Arbitrary Command Execution

EDB-ID:

25817


Author:

blahplok

Type:

webapps


Platform:

CGI

Date:

2005-06-12


source: https://www.securityfocus.com/bid/13937/info

JamMail is prone to a remote arbitrary command execution vulnerability.

This vulnerability may allow an attacker to supply arbitrary commands through the 'jammail.pl' script.

This can lead to various attacks including unauthorized access to an affected computer.

JamMail 1.8 is affected by this issue. 

http://www.example.com/cgi-bin/jammail.pl?job=showoldmail&mail=|command|