First published: Fri Dec 14 2007(Updated: )
SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse that introduces a PHP remote file inclusion vulnerability, which allows remote attackers to execute arbitrary code.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
SquirrelMail | =1.4.12 | |
SquirrelMail | =1.4.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6348 has a high severity level as it allows remote attackers to execute arbitrary PHP code.
To fix CVE-2007-6348, you should upgrade to SquirrelMail version 1.4.13 or later.
CVE-2007-6348 affects SquirrelMail versions 1.4.11 and 1.4.12.
CVE-2007-6348 is a PHP remote file inclusion vulnerability.
CVE-2007-6348 can be exploited by remote attackers with the ability to manipulate file inclusion mechanisms.