20070711 SquirrelMail G/PGP Plugin deleteKey() Command Injection VulnerabilityThird-party advisory
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=329 CVE-2005-1924
SquirrelMail G/PGP Encryption Plugin 2.0 - Command Execution
Record summary
CVE-2005-1924 has a selected CVSS score of 9.3; EIP currently links 2 catalogued exploits.
Description
The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharacters in (1) the fpr parameter to the deleteKey function in gpg_keyring.php, as called by (a) import_key_file.php, (b) import_key_text.php, and (c) keyring_main.php; and (2) the keyserver parameter to the gpg_recv_key function in gpg_key_functions.php, as called by gpg_options.php. NOTE: this issue may overlap CVE-2007-3636.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBSquirrelMail G/PGP Encryption Plugin 2.0 - Command ExecutionExploitDB exploitby jmp-espNot analyzed1 file
ExploitDBSquirrelMail G/PGP Encryption Plugin - 'deletekey()' Command InjectionExploitDB exploitby BackdooredNot analyzed1 file
References
Showing 12 of 1520070711 SquirrelMail G/PGP Plugin gpg_recv_key() Command Injection VulnerabilityThird-party advisory
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=331 37923vdb entry
http://osvdb.org/37923 37924vdb entry
http://osvdb.org/37924 26035Third-party advisory
http://secunia.com/advisories/26035 26424Third-party advisory
http://secunia.com/advisories/26424 GLSA-200708-08Vendor advisory
http://security.gentoo.org/glsa/glsa-200708-08.xml 20070711 True: SquirrelMail G/PGP Encryption Plug-in 2.0 Command Execution Vulnmailing list
http://www.attrition.org/pipermail/vim/2007-July/001710.html 20070711 SquirrelMail G/PGP Encryption Plug-in Remote Command Execution Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/473370/100/0/threaded 24874vdb entry
http://www.securityfocus.com/bid/24874 ADV-2007-2513vdb entry
http://www.vupen.com/english/advisories/2007/2513 squirrelmail-gpgp-keyring-command-execution(35355)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/35355