Title : SquirrelMail G/PGP Encryption Plugin Multiple Command Execution Vulnerabilities VUPEN ID : VUPEN/ADV-2007-2513 CVE ID : CVE-2005-1924 - CVE-2006-4169 - CVE-2007-3635 - CVE-2007-3778
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-12
Technical Description
Multiple vulnerabilities have been identified in SquirrelMail G/PGP Encryption Plugin, which could be exploited by attackers to execute arbitrary code or disclose sensitive information. These issues are caused by input validation errors in various scripts (e.g. "gpg_help.php", "gpg_key_functions.php", "gpg_hook_functions.php", or "gpg_keyring.php") when processing user-supplied parameters (e.g. "help", "keyserver", "messageSignedText" or "fpr"), which could be exploited by unauthenticated attackers or malicious users to include local files or inject and execute arbitrary commands with the privileges of the web server.