Security News No Fix for SquirrelMail Remote Code Execution Vulnerability

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
The PHP-based webmail package SquirrelMail suffers from a remote code execution vulnerability that could let attackers execute arbitrary commands on the target and compromise the system.

Dawid Golunski, a researcher with Legal Hackers discovered the vulnerability and reported it to the project’s maintainers in January. The researcher has previously uncovered similar remote code execution issues in the email libraries PHPMailer and SwiftMailer.

Developers behind the webmail package have reportedly been informed of the vulnerability but it’s unclear when or if it will be fixed.

Full Article. No Fix for SquirrelMail Remote Code Execution Vulnerability
 

katharn

Level 1
Apr 23, 2017
14
urgh i hope this can convince a customer to actually move away from that damned email server....
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top