vendor:
SquirrelMail
by:
pokleyzz
7.5
CVSS
HIGH
Remote Execution
78
CWE
Product Name: SquirrelMail
Affected Version From: 1.2.2005
Affected Version To: 1.2.2005
Patch Exists: YES
Related CWE: N/A
CPE: a:squirrelmail:squirrelmail:1.2.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux and Unix based operating systems
2002
SquirrelMail Remote Execution Vulnerability
A vulnerability has been reported in some versions of SquirrelMail. Reportedly, it is possible to corrupt the variable used to select a user's theme, and force the vulnerable script to execute arbitrary commands.
Mitigation:
Upgrade to the latest version of SquirrelMail.