LakeWeb Filemail CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.Referenceshttp://lakeweb.com/scripts/http://www.securityfocus.com/archive/1/11175https://exchange.xforce.ibmcloud.com/vulnerabilities/1400