7.5
CVSSv2

CVE-2001-1100

Published: 07/10/2001 Updated: 10/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

sendmessage.cgi in W3Mail 1.0.2, and possibly other CGI programs, allows remote malicious users to execute arbitrary commands via shell metacharacters in any field of the 'Compose Message' page.

Vulnerable Product Search on Vulmon Subscribe to Product

spencer miles w3mail 1.0.2