viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the cert parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
S_mime_plugin | Squirrelmail | 0.4 (including) | 0.4 (including) |
S_mime_plugin | Squirrelmail | 0.5 (including) | 0.5 (including) |