CVE

Id
10419  
CVE No.
CVE-2004-1993  
Status
Candidate  
Description
The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.  
Phase
Assigned (20050504)  
Votes
None (candidate not yet proposed)  
Comments