Description
Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Patch 55 before Patch 124
earlier before Patch 31
References
www.twcert.org.tw/tw/cp-132-7817-6ce29-1.html