Exploitation Summary
EIP tracks 2 public exploits for CVE-2003-0990.
PoCs published by Metasploit, including Metasploit module exploits/unix/webapp/squirrelmail_pgp_plugin.
AI-analyzed exploit summary This Metasploit module exploits a command execution vulnerability in the PGP plugin of SquirrelMail by sending a maliciously crafted email. The payload is embedded in the email body and executed when the email is viewed.
Description
The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters in the "To:" field.
Exploits (2)
This Metasploit module exploits a command execution vulnerability in the PGP plugin of SquirrelMail by sending a maliciously crafted email. The payload is embedded in the email body and executed when the email is viewed.
This Metasploit module exploits a command execution vulnerability in the SquirrelMail PGP plugin by sending a maliciously crafted email. The payload is embedded in the email body and executed when the email is viewed in SquirrelMail with the PGP plugin enabled.