First published: Sun Feb 06 2005(Updated: )
ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to execute arbitrary commands via shell metacharacters in a command line argument.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SquirrelMail Vacation Plugin | <=0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0183 is classified as a high severity vulnerability due to its potential to allow arbitrary command execution.
To fix CVE-2005-0183, upgrade to a version of the SquirrelMail Vacation plugin later than 0.15.
Local users who have access to the affected versions of the SquirrelMail Vacation plugin can exploit CVE-2005-0183.
Exploitation of CVE-2005-0183 can lead to unauthorized command execution on the server.
CVE-2005-0183 is caused by inadequate input validation in the Vacation plugin allowing shell metacharacters.