vendor:
SquirrelMail
by:
N/A
7,5
CVSS
HIGH
Arbitrary Variable Overwriting
20
CWE
Product Name: SquirrelMail
Affected Version From: <= 1.4.7
Affected Version To: <= 1.4.7
Patch Exists: YES
Related CWE: CVE-2006-4019
CPE: a:squirrelmail:squirrelmail
Metasploit:
https://www.rapid7.com/db/vulnerabilities/apple-osx-squirrelmail-cve-2006-4019/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2006-0668/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-21b7c550-2a22-11db-a6e2-000e0c2e438a/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2006-0668/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
SquirrelMail Arbitrary Variable Overwrite
SquirrelMail contains a vulnerability that may allow an authenticated user to overwrite important variables used by SquirrelMail, and ultimately read and or write arbitrary files to the system. Due to the nature of the vulnerability though other attacks may be possible. Again the attacker must first be authenticated, but in a real world scenario it usually is not that hard for an attacker to gain access to an email account that has a weak password via a dictionary attack or other methods.
Mitigation:
Update SquirrelMail installations to the latest version.