7.5
CVSSv2

CVE-2005-0152

Published: 02/02/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote malicious users to execute arbitrary code via "URL manipulation."

Vulnerable Product Search on Vulmon Subscribe to Product

squirrelmail squirrelmail 1.2.6

Vendor Advisories

Andrew Archibald discovered that the last update to squirrelmail which was intended to fix several problems caused a regression which got exposed when the user hits a session timeout  For completeness below is the original advisory text: Several vulnerabilities have been discovered in Squirrelmail, a commonly used webmail system The Common Vuln ...