Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2018-19518Argument Injection in Uw-imap

Severity
7.5HIGHNVD
EPSS
93.9%
top 0.13%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedNov 25
Latest updateJan 27

Description

University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_rimap function in c-client/imap4r1.c and the tcp_aopen function in osdep/unix/tcp_unix.c) without preventing argument injection, which might allow remote attackers to execute arbitrary OS commands if the IMAP server name is untrusted input (e.g., entered by a user of a web application) and if rsh has been replaced by a program with different argumen

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages4 packages

debiandebian/uw-imap< uw-imap 8:2007f~dfsg-6 (bookworm)
Debianuw-imap_project/uw-imap< 8:2007f~dfsg-6+1
NVDphp/php5.6.05.6.38+3

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 16.04, 18.04, 19.04

🔴Vulnerability Details

3
GHSA
GHSA-5qmr-54g6-4256: University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_r2022-05-13
OSV
CVE-2018-19518: University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_r2018-11-25
VulnCheck
PHP PHP Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')2018

💥Exploits & PoCs

3
Exploit-DB
PHP imap_open - Remote Code Execution (Metasploit)2018-11-29
Nuclei
PHP imap - Remote Command Execution
Metasploit
php imap_open Remote Code Execution

📋Vendor Advisories

4
CISA ICS
Festo Didactic SE MES PC2026-01-27
Ubuntu
UW IMAP vulnerability2019-10-21
Red Hat
php: imap_open() allows running arbitrary shell commands via mailbox parameter2018-11-19
Debian
CVE-2018-19518: uw-imap - University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in P...2018

💬Community

2
Bugzilla
CVE-2018-19518 php: imap_open() allows running arbitrary shell commands via mailbox parameter2018-11-28
Bugzilla
CVE-2018-19518 php: imap_open() allows running arbitrary shell commands via mailbox parameter [fedora-all]2018-11-28
CVE-2018-19518 — Argument Injection in Debian Uw-imap | cvebase