VendorsOmailomail_webmailall versions
Vulnerabilities

Omail Omail Webmail

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2004-1993
The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.
Published 2005-05-10 · Modified
10.0EPSS 0.047
CVE-2003-1202
The checklogin function in omail.pl for omail webmail 0.98.4 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) password, (2) domainname, or (3) username.
Published 2005-05-10 · Modified
10.0EPSS 0.036