>> SquirrelMail "compose.php" Variable Overwrite and Information Disclosure Vulnerability
Title : SquirrelMail "compose.php" Variable Overwrite and Information Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2006-3271 CVE ID : CVE-2006-4019
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-08-11
Technical Description
A vulnerability has been identified in SquirrelMail, which could be exploited by attackers to disclose or manipulate certain data. This flaw is due to an input validation error in the "compose.php" script, which could be exploited by attackers to overwrite certain variables and manipulate other users' preferences and attachments.