OSVDB ID: 27917

Title: SquirrelMail compose.php Arbitrary Variable Manipulation

Info

Disclosure

Aug 11, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Squirrelmail contains a flaw that may allow a malicious user to overwrite arbitrary variables in the file compose.php. It is possible that the flaw may allow user preferences or file attachments to be overwritten, resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified
OSVDB: Web Related

Solution

Upgrade to version 1.4.8 or higher, as it has been reported to fix this vulnerability. In addition, the SquirrelMail Project Team has released a patch for version 1.4.7.

Products

SquirrelMail Project Team

Squirrelmail

1.4.0 RC 1
1.4.0 RC 2a
1.4.0
1.4.1
1.4.2
1.4.3-RC1
1.4.3
1.4.3a
1.4.4 RC1
1.4.4
1.4.5
1.4.6
1.4.7
1.4.5 Release Candidate 1
1.4.6 Release Candidate 1

References

Credit

  • James Bercegay - securitygulftech.org - GulfTech Security Research


Direct URL: http://osvdb.org/27917