Back to Database
Status published
Critical
CVE-2004-2284
The read_list_from_file function in vacation.pl for OpenWebmail before 2.32 20040629...
Vulnerability Description
The read_list_from_file function in vacation.pl for OpenWebmail before 2.32 20040629 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename argument.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-2284
Credits & Attribution
No credits recorded in the NVD database.
References
More from open webmail
View All →CVE-2007-4172
Multiple cross-site scripting (XSS) vulnerabilities in Open Webmail (OWM) 2.52...
Medium
4.3
CVE-2006-3233
Cross-site scripting (XSS) vulnerability in openwebmail-read.pl in Open WebMail (OWM)...
Medium
4.3
CVE-2006-3229
Cross-site scripting (XSS) vulnerability in Open WebMail (OWM) 2.52, and...
Medium
4.3
CVE-2006-2190
Cross-site scripting (XSS) vulnerability in ow-shared.pl in OpenWebMail (OWM) 2.51...
Medium
6.8
CVE-2005-2863
Cross-site scripting (XSS) vulnerability in openwebmail-main.pl in OpenWebMail 2.41 allows...
Medium
4.3
Affected Vendor
open webmail
View all reports →Affected Software
open webmail
Vulnerable Versions:
1.7, 1.8, 1.71, 1.81, 1.90, 2.20, 2.21, 2.30, 2.31, 2.32
Timeline
Official Publish:
July 19th, 2005
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.