|
Vulnerability Assessment & Network Security Forums |
|||||||||
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> CGI abuses >> SquirrelMail plugins Parameter Local File Include Vulnerability Vulnerability Assessment Details
|
SquirrelMail plugins Parameter Local File Include Vulnerability |
||
Tries to read file using SquirrelMail Detailed Explanation for this Vulnerability Assessment Summary : The remote web server contains a PHP script that is affected by a local file include issue. Description : The version of SquirrelMail installed on the remote fails to properly sanitize user-supplied input to the 'tests' parameter of the 'functions/test.php' script before using it in a PHP 'include_once()' function. Provided PHP's 'register_globals' setting is enabled, an unauthenticated attacker may be able to exploit this issue to view arbitrary files or to execute arbitrary PHP code on the remote host, subject to the rights of the web server user id. See also : http://www.securityfocus.com/archive/1/435605/30/0/threaded http://www.squirrelmail.org/security/issue/2006-06-01 Solution : Disable PHP's 'register_globals' setting or apply the patch referenced in the project's advisory above. Network Security Threat Level: High / CVSS Base Score : 7.0 (AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N) Networks Security ID: 18231 Vulnerability Assessment Copyright: This script is Copyright (C) 2006 Tenable Network Security |
||
Cables, Connectors |
LSI 9305-16i SATA SAS 12Gbs RAID Controller PCIe 3.0 x8 IT-Mode 4* 8643 SATA
$229.99
HPE 869102-001 Smart Array E208i-a SR Gen10 Storage Controller RAID SP: 871039
$116.99
Lot of 4 - Genuine Dell (62P9H) PERC H710 512MB Mini Blade 6Gbps SAS Raid
$44.99
Dell (WMVFG) PERC H730 1GB NV Mini Raid Controller /w Battery - Blade
$44.99
Inspur LSI 9300-8i Raid Card 12Gbps HBA HDD Controller High Profile IT MODE
$15.98
LSI MegaRAID 9361-8i 12Gb PCIe 8-Port SAS/SATA RAID 1Gb w/BBU/CacheVault/License
$39.95
Dell PowerEdge RAID Controller HBA330 12Gbs PCIe 3.0 SAS SATA J7TNV Low Profile
$29.00
LSI MegaRaid 9361-8i 12Gbps SAS / SATA Raid Controller PCIe x8 3.0 Tested
$29.00
4 Bay RAID External Hard Drive Enclosure for 2.5/3.5" SATA HDD/SSD
$79.99
ORICO Multi Bay RAID Hard Drive Enclosure USB 3.0/ Type-C For 2.5/3.5'' HDD SSDs
$143.99
|
||
No Discussions have been posted on this vulnerability. |