Loading...
Loading...
Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl's @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious openwebmail-shared.pl executable.
December 31, 2003
April 16, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2003-1426
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.