CVE
- Id
- 1134
- CVE No.
- CVE-1999-1154
- Status
- Candidate
- Description
- LakeWeb Filemail CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.
- Phase
- Proposed (20010912)
- Votes
- ACCEPT(2) Cole, Frech | NOOP(3) Christey, Foat, Wall
- Comments
- Christey> I confirmed this problem via visual inspection of the | source code in http://www.lakeweb.com/scripts/filemail.zip | Line 82 has an insufficient check for shell metacharacters | that doesn"t exclude semicolons. Line 129 is the | call where the metacharacters are injected. | | Need to add "filemail.pl" to the description.