CVE
- Id
- 3963
- CVE No.
- CVE-2001-1159
- Status
- Candidate
- Description
- load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows remote attackers to (1) view sensitive files via the config_php and data_dir options, and (2) execute arbitrary code by using options_order.php to upload a message that could be interpreted as PHP.
- Phase
- Proposed (20020315)
- Votes
- ACCEPT(3) Baker, Frech, Green | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese
- Comments
- CHANGE> [Baker changed vote from REVIEWING to ACCEPT]