CVE-2006-2842: Squirrelmail <=1.4.6 - Local File Inclusion

CVE-2006-2842: Squirrelmail <=1.4.6 - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享
CVE-2006-2842: Squirrelmail <=1.4.6 - Local File Inclusion
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2006-2842: Squirrelmail <=1.4.6 – Local File Inclusion

漏洞描述

SquirrelMail 1.4.6 and earlier versions are susceptible to a PHP local file inclusion vulnerability in functions/plugin.php if register_globals is enabled and magic_quotes_gpc is disabled. This allows remote attackers to execute arbitrary PHP code via a URL in the plugins array parameter.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享