Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2006-4169
Description:Multiple directory traversal vulnerabilities in the G/PGP (GPG) Plugin 2.0, and 2.1dev before 20070614, for Squirrelmail allow remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the help parameter to (1) gpg_help.php or (2) gpg_help_base.php.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2006-4169
BugTraq ID: 24874
http://www.securityfocus.com/bid/24874
http://security.gentoo.org/glsa/glsa-200708-08.xml
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=555
http://osvdb.org/37932
http://osvdb.org/37933
http://secunia.com/advisories/26035
http://secunia.com/advisories/26424
http://www.vupen.com/english/advisories/2007/2513
XForce ISS Database: squirrelmail-gpgp-help-file-include(35362)
https://exchange.xforce.ibmcloud.com/vulnerabilities/35362




© 1998-2025 E-Soft Inc. All rights reserved.