Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-2284
CVE-2004-2284
Description
The read_list_from_file function in vacation.pl for OpenWebmail before 2.32 20040629 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename argument.
Affected products
10cpe:2.3:a:open_webmail:open_webmail:1.7:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:open_webmail:open_webmail:1.7:*:*:*:*:*:*:*
- cpe:2.3:a:open_webmail:open_webmail:1.71:*:*:*:*:*:*:*
- cpe:2.3:a:open_webmail:open_webmail:1.8:*:*:*:*:*:*:*
- cpe:2.3:a:open_webmail:open_webmail:1.81:*:*:*:*:*:*:*
- cpe:2.3:a:open_webmail:open_webmail:1.90:*:*:*:*:*:*:*
- cpe:2.3:a:open_webmail:open_webmail:2.20:*:*:*:*:*:*:*
- cpe:2.3:a:open_webmail:open_webmail:2.21:*:*:*:*:*:*:*
- cpe:2.3:a:open_webmail:open_webmail:2.30:*:*:*:*:*:*:*
- cpe:2.3:a:open_webmail:open_webmail:2.31:*:*:*:*:*:*:*
- cpe:2.3:a:open_webmail:open_webmail:2.32:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- openwebmail.org/openwebmail/download/cert/advisories/SA-04:04.txtnvdPatchVendor Advisory
- secunia.com/advisories/12017nvdPatchVendor Advisory
- securitytracker.com/idnvdPatch
- www.osvdb.org/7474nvdPatch
- www.securityfocus.com/bid/10637nvdPatch
- exchange.xforce.ibmcloud.com/vulnerabilities/16549nvd
News mentions
0No linked articles in our index yet.