Total vulnerabilities in the database
A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.
Software | From | Fixed in |
---|---|---|
squirrelmail / squirrelmail | 1.4.22 | 1.4.22.x |
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 7.0 | 7.0.x |