Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23040
HistoryApr 10, 2020 - 12:13 a.m.

Arbitrary Code Execution

2020-04-1000:13:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.281 Low

EPSS

Percentile

96.9%

squirrelmail is vulnerable to arbitrary code execution. A local file disclosure flaw was found in the way SquirrelMail loads plugins. If register_globals is on and magic_quotes_gpc is off, it became possible for an unauthenticated remote user to view the contents of arbitrary local files the web server has read-access to. This configuration is neither default nor safe, and configuring PHP with the register_globals set on is dangerous and not recommended.

References