Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SquirrelMail 1.2.7 and earlier allows remote attackers to determine the absolute pathname of the options.php script via a malformed optpage file argument, which generates an error message when the file cannot be included in the script.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SquirrelMail Options.PHP Web脚本绝对路径泄露漏洞
Vulnerability Description
SquirrelMail是一款PHP编写的WEBMAIL程序。 SquirrelMail的'options.php'脚本对参数处理不正确,远程攻击者可以利用这个漏洞获得脚本绝对路径信息。 攻击者可以提供畸形数据作为参数给'options.php'脚本,这个脚本就会产生错误信息,而返回给客户端的操作系统包含'options.php'脚本的绝对路径信息。攻击者可能利用这个信息进一步对系统进行攻击。 <*链接:https://www.redhat.com/support/errata/RHSA-2002-204
CVSS Information
N/A
Vulnerability Type
N/A