CVE Vulnerabilities

CVE-2003-0990

Published: Jan 20, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters in the To: field.

Affected Software

NameVendorStart VersionEnd Version
Gpg_pluginSquirrelmail1.1 (including)1.1 (including)
SquirrelmailSquirrelmail1.4.0 (including)1.4.0 (including)

References