Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
SquirrelMail G/PGP Encryption Plug-in Remote Command Execution Vulnerability Jul 11 2007 02:10PM
does_not_exist jmp-esp kicks-ass net
SquirrelMail G/PGP Encryption Plug-in Remote Command Execution Vulnerability

Bugtraq ID: 24782

-----------------------------

There are various vulnerabilities in this software! One is in keyring_main.php!
$fpr is not escaped from shellcommands!

testbox:/home/w00t# cat /tmp/w00t
cat: /tmp/w00t: N...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus