SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  SquirrelMail Remote Code Execution 2

Category: WEB-ATTACKS      

SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mishandled in a popen call. It's possible to exploit this vulnerability to execute arbitrary shell commands on the remote server.


Relevant Information