The checklogin function in omail.pl for omail webmail 0.98.4 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) password, (2) domainname, or (3) username.
| Software | From | Fixed in |
|---|---|---|
| omail / omail_webmail | 0.97.3 | 0.97.3.x |
| omail / omail_webmail | 0.98.4 | 0.98.4.x |