10
CVSSv2

CVE-2002-0516

Published: 12/08/2002 Updated: 05/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

SquirrelMail 1.2.5 and previous versions allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

squirrelmail squirrelmail 1.2.0

squirrelmail squirrelmail 1.2.1

squirrelmail squirrelmail 1.2.2

squirrelmail squirrelmail 1.2.3

squirrelmail squirrelmail 1.2.5

squirrelmail squirrelmail 1.2.4

Exploits

source: wwwsecurityfocuscom/bid/4385/info SquirrelMail is a feature rich webmail program implemented in the PHP4 language It is available for Linux and Unix based operating systems SquirrelMail allows for extended functionality through a plugin system A vulnerability has been reported in some versions of SquirrelMail Reportedly, it i ...