Total vulnerabilities in the database
The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program. NOTE: this issue exists because of an incomplete fix for CVE-2009-1579.
Software | From | Fixed in |
---|---|---|
squirrelmail / squirrelmail | 1.4.0-r1 | 1.4.0-r1.x |
squirrelmail / squirrelmail | 1.2.7 | 1.2.7.x |
squirrelmail / squirrelmail | 1.2.6-rc1 | 1.2.6-rc1.x |
squirrelmail / squirrelmail | 1.2.9 | 1.2.9.x |
squirrelmail / squirrelmail | 1.4.1 | 1.4.1.x |
squirrelmail / squirrelmail | 1.4.0 | 1.4.0.x |
squirrelmail / squirrelmail | 1.2.6 | 1.2.6.x |
squirrelmail / imap_general.php | 1.2.2 | 1.2.2.x |
squirrelmail / squirrelmail | 1.2.10 | 1.2.10.x |
squirrelmail / squirrelmail | 1.2.5 | 1.2.5.x |
squirrelmail / squirrelmail | 1.2.8 | 1.2.8.x |
squirrelmail / squirrelmail | 1.2.11 | 1.2.11.x |