Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiers in the xtellmail command.
https://exchange.xforce.ibmcloud.com/vulnerabilities/20414
http://www.security.org.sg/vuln/dmail31a.html
http://securitytracker.com/id?1013885