PT-2005-1211 · Squirrelmail+1 · Squirrelmail+1

Manoel Zaninetti

·

Published

2005-01-24

·

Updated

2017-10-11

·

CVE-2005-0103

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SquirrelMail versions prior to 1.4.4
Description The issue allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code. This is related to a remote file inclusion vulnerability in the webmail.php file.
Recommendations For versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the webmail.php file to minimize the risk of exploitation.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2005-0103
RHSA-2005:099
RHSA-2005:135
RHSA-2005_099
RHSA-2005_135

Affected Products

Red Hat
Squirrelmail