CVE

Id
1134  
CVE No.
CVE-1999-1154  
Status
Candidate  
Description
LakeWeb Filemail CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.  
Phase
Proposed (20010912)  
Votes
ACCEPT(2) Cole, Frech | NOOP(3) Christey, Foat, Wall  
Comments
Christey> I confirmed this problem via visual inspection of the | source code in http://www.lakeweb.com/scripts/filemail.zip | Line 82 has an insufficient check for shell metacharacters | that doesn"t exclude semicolons. Line 129 is the | call where the metacharacters are injected. | | Need to add "filemail.pl" to the description.