Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-3636. PoCs published by Stefan Esser.
AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in the SquirrelMail G/PGP plugin. The vulnerability allows authenticated users to execute arbitrary system commands by injecting them into the 'fpr' parameter of a POST request to keyring_main.php.
Description
Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via unspecified vectors. NOTE: this information is based upon a vague pre-advisory from a reliable researcher.
Exploits (1)
This exploit demonstrates a command injection vulnerability in the SquirrelMail G/PGP plugin. The vulnerability allows authenticated users to execute arbitrary system commands by injecting them into the 'fpr' parameter of a POST request to keyring_main.php.