The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.
| Software | From | Fixed in |
|---|---|---|
| omail / omail_webmail | 0.97.3 | 0.97.3.x |
| omail / omail_webmail | 0.98.3 | 0.98.3.x |
| omail / omail_webmail | 0.98.5 | 0.98.5.x |