Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-1579

Опубликовано: 10 мая 2009
Источник: redhat
CVSS2: 7.5

Описание

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=500360SquirrelMail: Server-side code injection in map_yp_alias username map

7.5 High

CVSS2

Связанные уязвимости

ubuntu
около 16 лет назад

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.

nvd
около 16 лет назад

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.

debian
около 16 лет назад

The map_yp_alias function in functions/imap_general.php in SquirrelMai ...

github
около 3 лет назад

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.

oracle-oval
около 16 лет назад

ELSA-2009-1066: squirrelmail security update (IMPORTANT)

7.5 High

CVSS2