[] NeoSense

JamMail 1.8 - Jammail.pl Arbitrary Command Execution

Author: blahplok
type: webapps
platform: cgi
port: 
date_added: 2005-06-12 
date_updated: 2013-05-30 
verified: 1 
codes: CVE-2005-1959;OSVDB-17339 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/13937/info

JamMail is prone to a remote arbitrary command execution vulnerability.

This vulnerability may allow an attacker to supply arbitrary commands through the 'jammail.pl' script.

This can lead to various attacks including unauthorized access to an affected computer.

JamMail 1.8 is affected by this issue.

http://www.example.com/cgi-bin/jammail.pl?job=showoldmail&mail=|command|