Lucene search

K
securityvulnsJLXSECURITYVULNS:VULN:2866
HistoryMay 31, 2003 - 12:00 a.m.

W3Mail multiple bugs

2003-05-3100:00:00
JLX
vulners.com
21

delete.cgi invokes external program though system() call without escaping shell characters. It's possible to change server configuration without administrator's permissions. All passwords are stored in Base64 encoding.

CPENameOperatorVersion
w3maileq1.0