>> SquirrelMail "plugins" Parameter Handling Local File Inclusion Vulnerability
Title : SquirrelMail "plugins" Parameter Handling Local File Inclusion Vulnerability VUPEN ID : VUPEN/ADV-2006-2101 CVE ID : CVE-2006-2842
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-06-01
Technical Description
A vulnerability has been identified in SquirrelMail, which could be exploited by remote attackers to gain knowledge of sensitive information. This flaw is due to an input validation error in the "use_plugin()" [functions/plugin.php] function that does not validate the "plugins" array parameter, which could be exploited by remote attackers to include or disclose the contents of local files with the privileges of the web server.