SquirrelMail Theme Remote Command Execution Vulnerability
BID:4385
Info
SquirrelMail Theme Remote Command Execution Vulnerability
| Bugtraq ID: | 4385 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2002 12:00AM |
| Updated: | Mar 28 2002 12:00AM |
| Credit: | Discovered by pokleyzz sakamaniaka <[email protected]>. |
| Vulnerable: |
SquirrelMail SquirrelMail 1.2.5 SquirrelMail SquirrelMail 1.2.4 SquirrelMail SquirrelMail 1.2.3 SquirrelMail SquirrelMail 1.2.2 SquirrelMail SquirrelMail 1.2.1 SquirrelMail SquirrelMail 1.2 .0 |
| Not Vulnerable: |
SquirrelMail SquirrelMail 1.2.6 |
Discussion
SquirrelMail Theme Remote Command Execution Vulnerability
SquirrelMail is a feature rich webmail program implemented in the PHP4 language. It is available for Linux and Unix based operating systems. SquirrelMail allows for extended functionality through a plugin system.
A vulnerability has been reported in some versions of SquirrelMail. Reportedly, it is possible to corrupt the variable used to select a user's theme, and force the vulnerable script to execute arbitrary commands.
SquirrelMail is a feature rich webmail program implemented in the PHP4 language. It is available for Linux and Unix based operating systems. SquirrelMail allows for extended functionality through a plugin system.
A vulnerability has been reported in some versions of SquirrelMail. Reportedly, it is possible to corrupt the variable used to select a user's theme, and force the vulnerable script to execute arbitrary commands.
Exploit / POC
SquirrelMail Theme Remote Command Execution Vulnerability
An exploit has been provided by pokleyzz sakamaniaka <[email protected]>:
An exploit has been provided by pokleyzz sakamaniaka <[email protected]>:
Solution / Fix
SquirrelMail Theme Remote Command Execution Vulnerability
Solution:
The vendor has addressed this issue in SquirrelMail version 1.2.6. Users are advised to upgrade.
SquirrelMail SquirrelMail 1.2 .0
SquirrelMail SquirrelMail 1.2.1
SquirrelMail SquirrelMail 1.2.2
SquirrelMail SquirrelMail 1.2.3
SquirrelMail SquirrelMail 1.2.4
SquirrelMail SquirrelMail 1.2.5
Solution:
The vendor has addressed this issue in SquirrelMail version 1.2.6. Users are advised to upgrade.
SquirrelMail SquirrelMail 1.2 .0
-
SquirrelMail squirrelmail-1.2.6
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.2.1
-
SquirrelMail squirrelmail-1.2.6
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.2.2
-
SquirrelMail squirrelmail-1.2.6
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.2.3
-
SquirrelMail squirrelmail-1.2.6
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.2.4
-
SquirrelMail squirrelmail-1.2.6
http://www.squirrelmail.org/download.php
SquirrelMail SquirrelMail 1.2.5
-
SquirrelMail squirrelmail-1.2.6
http://www.squirrelmail.org/download.php
References
SquirrelMail Theme Remote Command Execution Vulnerability
References:
References:
- BID 2968: SquirrelMail Remote Command Execution Vulnerability (SecurityFocus)
- XMB Homepage (XMB)