CVE
- Id
- 27895
- CVE No.
- CVE-2007-4538
- Status
- Candidate
- Description
- email_in.pl in Bugzilla 2.23.4 through 3.0.0 allows remote attackers to execute arbitrary commands via the -f (From address) option to the Email::Send::Sendmail function, probably involving shell metacharacters.
- Phase
- Assigned (20070827)
- Votes
- None (candidate not yet proposed)
- Comments