First published: Tue Dec 31 2002(Updated: )
The spell checker plugin (check_me.mod.php) for SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary commands via a modified sqspell_command parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SquirrelMail | =1.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1650 is rated as a critical vulnerability due to the potential for remote command execution.
To fix CVE-2002-1650, upgrade your SquirrelMail installation to version 1.2.3 or later.
CVE-2002-1650 allows remote attackers to execute arbitrary commands on the server.
CVE-2002-1650 affects SquirrelMail versions prior to 1.2.3, specifically version 1.2.2.
The vulnerability in CVE-2002-1650 resides in the spell checker plugin (check_me.mod.php) of SquirrelMail.