Squirrelmail G/PGP Encryption Plugin Remote Command Execution Vulnerability
BID:9296
Info
Squirrelmail G/PGP Encryption Plugin Remote Command Execution Vulnerability
| Bugtraq ID: | 9296 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0990 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 25 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | Discovery credited to [email protected]. |
| Vulnerable: |
SquirrelMail G/PGP Encryption Plugin 1.1 SquirrelMail G/PGP Encryption Plugin 1.0.2 SquirrelMail G/PGP Encryption Plugin 1.0.1 SquirrelMail G/PGP Encryption Plugin 1.0 |
| Not Vulnerable: | |
Discussion
Squirrelmail G/PGP Encryption Plugin Remote Command Execution Vulnerability
A problem in the handling of some types of input passed to the Squirrelmail G/PGP Plugin has been discovered. This issue may make it possible for a remote user to gain unauthorized access to a system hosting the vulnerable application.
A problem in the handling of some types of input passed to the Squirrelmail G/PGP Plugin has been discovered. This issue may make it possible for a remote user to gain unauthorized access to a system hosting the vulnerable application.
Exploit / POC
Squirrelmail G/PGP Encryption Plugin Remote Command Execution Vulnerability
No exploit is required for this vulnerability. This issue may be exploited by placing malicious commands in the form of ";command;" in the To: line.
No exploit is required for this vulnerability. This issue may be exploited by placing malicious commands in the form of ";command;" in the To: line.
Solution / Fix
Squirrelmail G/PGP Encryption Plugin Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Squirrelmail G/PGP Encryption Plugin Remote Command Execution Vulnerability
References:
References:
- Plugin Page (Squirrelmail)
- XMB Homepage (XMB)
- Re: Reported Command Injection in Squirrelmail GPG ("Brian G. Peterson"
)