Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v10.5 - Exploits Update (Wed Jul 14 2010)

SquirrelMail map_yp_alias Command Injection Exploit

Exploits/Remote  [Linux]




• Wed Jul 14 2010
The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program. This module works if map:map_yp_alias is set as the imap server address in config.php, which is not the default setting.

Exploits Vulnerabiltiy: CVE-2009-1381



< Back to Product Updates