The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters in the To: field.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gpg_plugin | Squirrelmail | 1.1 (including) | 1.1 (including) |
Squirrelmail | Squirrelmail | 1.4.0 (including) | 1.4.0 (including) |