CORE IMPACT v10.5 - Exploits Update (Wed Jul 14 2010)
SquirrelMail map_yp_alias Command Injection Exploit
Exploits/Remote [Linux]
Wed Jul 14 2010
The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program. This module works if map:map_yp_alias is set as the imap server address in config.php, which is not the default setting.
Exploits Vulnerabiltiy: CVE-2009-1381











