susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries.
| Software | From | Fixed in |
|---|---|---|
| suse / office_server | - | - |
| suse / suse_linux | 8 | 8.x |
| suse / suse_linux_openexchange_server | 4.0 | 4.0.x |
| suse / suse_linux | 8.1 | 8.1.x |