Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Matt Wright FormMail Remote Command Execution Vulnerability

FormMail is a widely-used web-based e-mail gateway, which allows form-based input to be emailed to a specified user.

User supplied data (from the "recipient" hidden field) is passed to a Perl OPEN function without proper input verification, allowing the use of the command separation shell metacharacter (;) to execute arbitrary commands on the remote host. Consequences could range from destruction of data and web site defacement to elevation of privileges through locally exploitable vulnerabilities.







 

Privacy Statement
Copyright 2009, SecurityFocus