Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SquirrelMail选择主题远程执行任意命令漏洞
Vulnerability Description
SquirrelMail是一个多功能的用PHP4实现的Webmail程序,可运行于Linux/Unix类操作系统下,它允许利用plugin来扩展系统的功能。 某些版本的SquirrelMail程序对用户输入未做充分过滤,可以使远程攻击者在主机上执行任意命令。 程序脚本对用户选择主题的变量未做充分过滤,远程攻击者可能通过构造特定的输入可能在主机上以Web服务器进程身份执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A