Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SquirrelMail 'functions/imap_general.php'任意命令执行漏洞
Vulnerability Description
SquirrelMail是一款PHP编写的WEBMAIL程序。 SquirrelMail 1.4.18之前版本和NaSMail 1.7之前版本中的functions/imap_general.php的map_yp_alias函数中存在任意命令执行漏洞。没有正确地过滤对map_yp_alias用户名映射函数所传送的输入便在shell命令中使用,这可能导致执行任意服务器端脚本。
CVSS Information
N/A
Vulnerability Type
N/A