Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SquirrelMail Theme Remote Command Execution Vulnerability

SquirrelMail is a feature rich webmail program implemented in the PHP4 language. It is available for Linux and Unix based operating systems. SquirrelMail allows for extended functionality through a plugin system.

A vulnerability has been reported in some versions of SquirrelMail. Reportedly, it is possible to corrupt the variable used to select a user's theme, and force the vulnerable script to execute arbitrary commands.







 

Privacy Statement
Copyright 2009, SecurityFocus