First published: Wed Feb 02 2005(Updated: )
PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SquirrelMail | =1.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0152 has been classified with a critical severity level as it allows remote attackers to execute arbitrary code.
To fix CVE-2005-0152, update SquirrelMail to a version that is not vulnerable, preferably above 1.2.6.
CVE-2005-0152 affects SquirrelMail version 1.2.6.
CVE-2005-0152 enables remote file inclusion attacks that can lead to arbitrary code execution.
While CVE-2005-0152 was disclosed in 2005, it remains relevant for environments still using the vulnerable version of SquirrelMail.