Squirrelmail contains a flaw that may allow a malicious user to overwrite arbitrary variables in the file compose.php. It is possible that the flaw may allow user preferences or file attachments to be overwritten, resulting in a loss of integrity.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
OSVDB:
Web Related
Solution
Upgrade to version 1.4.8 or higher, as it has been reported to fix this vulnerability. In addition, the SquirrelMail Project Team has released a patch for version 1.4.7.