CVE

Id
3963  
CVE No.
CVE-2001-1159  
Status
Candidate  
Description
load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows remote attackers to (1) view sensitive files via the config_php and data_dir options, and (2) execute arbitrary code by using options_order.php to upload a message that could be interpreted as PHP.  
Phase
Proposed (20020315)  
Votes
ACCEPT(3) Baker, Frech, Green | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese  
Comments
CHANGE> [Baker changed vote from REVIEWING to ACCEPT]