EMU Webmail allows local users to execute arbitrary programs via a .. (dot dot) in the HTTP Host header that points to a Trojan horse configuration file that contains a pageroot specifier that contains shell metacharacters.
| Software | From | Fixed in |
|---|---|---|
| emumail / emumail_unix | 5.0 | 5.0.x |
| emumail / emumail_red_hat_linux | 5.0 | 5.0.x |
| emumail / emumail_red_hat_linux | 5.1 | 5.1.x |
| emumail / emumail_unix | 5.1 | 5.1.x |
| emumail / emumail | 3.0 | 3.0.x |