Vulnerability Description
PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plugins array parameter. NOTE: this issue has been disputed by third parties, who state that Squirrelmail provides prominent warnings to the administrator when register_globals is enabled. Since the varieties of administrator negligence are uncountable, perhaps this type of issue should not be included in CVE. However, the original developer has posted a security advisory, so there might be relevant real-world environments under which this vulnerability is applicable
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Squirrelmail | Squirrelmail | <= 1.4.6 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc
- http://docs.info.apple.com/article.html?artnum=306172
- http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html
- http://secunia.com/advisories/20406PatchVendor Advisory
- http://secunia.com/advisories/20931
- http://secunia.com/advisories/21159
- http://secunia.com/advisories/21262
- http://secunia.com/advisories/26235
- http://securitytracker.com/id?1016209
- http://squirrelmail.cvs.sourceforge.net/squirrelmail/squirrelmail/functions/globPatch
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:101
- http://www.novell.com/linux/security/advisories/2006_17_sr.html
- http://www.redhat.com/support/errata/RHSA-2006-0547.html
- http://www.securityfocus.com/archive/1/435605/100/0/threaded
- http://www.securityfocus.com/bid/18231Exploit
FAQ
What is CVE-2006-2842?
CVE-2006-2842 is a vulnerability with a CVSS score of 7.5 (HIGH). PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute a...
How severe is CVE-2006-2842?
CVE-2006-2842 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-2842?
Check the references section above for vendor advisories and patch information. Affected products include: Squirrelmail Squirrelmail.