5.5
CVSSv2

CVE-2006-4169

Published: 15/07/2007 Updated: 20/07/2017
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in the G/PGP (GPG) Plugin 2.0, and 2.1dev prior to 20070614, for Squirrelmail allow remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the help parameter to (1) gpg_help.php or (2) gpg_help_base.php.

Vulnerable Product Search on Vulmon Subscribe to Product

squirrelmail gpg plugin 2.0

squirrelmail gpg plugin 2.1_dev