Secunia Logo
 
CVE Reference: CVE-2006-2842
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-2842

Description:
** DISPUTED ** PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plugins array parameter. NOTE: this issue has been disputed by third parties, who state that Squirrelmail provides prominent warnings to the administrator when register_globals is enabled. Since the varieties of administrator negligence are uncountable, perhaps this type of issue should not should not be included in CVE. However, the original developer has posted a security advisory, so there might be relevant real-world environments under which this vulnerability is applicable.

CVE Status:
Candidate

References:

SUSE
  http://www.novell.com/linux/security/advisories/2006_17_sr.html

ST
  1016209

SGI

SAID
  Secunia Advisory: SA20406
  Secunia Advisory: SA20931
  Secunia Advisory: SA21159
  Secunia Advisory: SA21262
  Secunia Advisory: SA26235

REDHAT
  http://www.redhat.com/support/errata/RHSA-2006-0547.html

MANDRIVA
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:101

CONFIRM
  http://docs.info.apple.com/article.html?artnum=306172
  http://www.squirrelmail.org/security/issue/2006-06-01
  http://squirrelmail.cvs.sourceforge.net/squirrelmail/squirrelmail/functions/global.php?r1=1.27.2.16&r2=1.27.2.17&view=patch&pathrev=SM-1_4-STABLE

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/435605/100/0/threaded

BID
  18231
  25159

APPLE
  http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html


Return to the previous page.