W3Mail Remote Arbitrary Command Execution Vulnerability

BID:3673

Info

W3Mail Remote Arbitrary Command Execution Vulnerability

Bugtraq ID: 3673
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: Oct 07 2001 12:00AM
Updated: Oct 07 2001 12:00AM
Credit: Discovered by Emanuel Almeida <[email protected]> and posted to the BugTraq mailing list on October 7, 2001.
Vulnerable: CascadeSoft W3Mail 1.0.2
Not Vulnerable: CascadeSoft W3Mail 1.0.3

Discussion

W3Mail Remote Arbitrary Command Execution Vulnerability

W3Mail is a full featured open source web mail application implemented as a collection of Perl scripts that runs on Linux and Unix systems. It includes support for sending mail.

When sending email, values passed as script parameters are used as part of a shell command. Shell meta characters are not properly filtered from this input. A maliciously formed URL submitted to the script could contain additional shell commands, which would then be executed by the web server user (generally 'nobody'). As a result, an attacker may execute arbitrary code on the vulnerable server.

Earlier versions of W3Mail may also be vulnerable.

Exploit / POC

W3Mail Remote Arbitrary Command Execution Vulnerability

No exploit code is required to take advantage of this issue.

Solution / Fix

W3Mail Remote Arbitrary Command Execution Vulnerability

Solution:
Version 1.0.3 of W3Mail fixes this vulnerability.

References

W3Mail Remote Arbitrary Command Execution Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report