Lucene search

K
nvd[email protected]NVD:CVE-2007-6348
HistoryDec 14, 2007 - 7:46 p.m.

CVE-2007-6348

2007-12-1419:46:00
CWE-94
web.nvd.nist.gov
5

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.101

Percentile

94.9%

SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse that introduces a PHP remote file inclusion vulnerability, which allows remote attackers to execute arbitrary code.

Affected configurations

Nvd
Node
squirrelmailsquirrelmailMatch1.4.11
OR
squirrelmailsquirrelmailMatch1.4.12

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.101

Percentile

94.9%

Related for NVD:CVE-2007-6348