Title : SquirrelMail S/MIME Plugin Command Injection Vulnerability VUPEN ID : VUPEN/ADV-2005-0115 CVE ID : CVE-2005-0239 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-02-08
Technical Description
A command injection vulnerability was reported in the Squirrelmail S/MIME plugin, which may be exploited by malicious users to compromise a vulnerable system. The problem exists due to a missing input sanitising error when handling the "cert" [viewcert.php] variable, which could be exploited by authenticated web mail users to execute arbitrary commands.