CVE-2007-6348
Estado: ModificadaMedia (6.8)—
SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse that introduces a PHP remote file inclusion vulnerability, which allows remote attackers to execute arbitrary code.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.91%
- Percentil entre todas las CVEs puntuadas: 90
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-94
Referencias
- http://marc.info/?l=bugtraq&m=119765643909825&w=2
- http://marc.info/?l=squirrelmail-devel&m=119756462212214&w=2
- http://marc.info/?l=squirrelmail-devel&m=119765235203392&w=2
- http://osvdb.org/42633
- http://secunia.com/advisories/28095
- http://www.securityfocus.com/archive/1/485037/100/0/threaded
- http://www.squirrelmail.org/index.php
- http://marc.info/?l=bugtraq&m=119765643909825&w=2
- http://marc.info/?l=squirrelmail-devel&m=119756462212214&w=2
- http://marc.info/?l=squirrelmail-devel&m=119765235203392&w=2
- http://osvdb.org/42633
- http://secunia.com/advisories/28095
- http://www.securityfocus.com/archive/1/485037/100/0/threaded
- http://www.squirrelmail.org/index.php
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-6348",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-12-14T19:46:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=119765643909825&w=2",
"source": "secalert@redhat.com"
},
{
"url": "http://marc.info/?l=squirrelmail-devel&m=119756462212214&w=2",
"source": "secalert@redhat.com"
},
{
"url": "http://marc.info/?l=squirrelmail-devel&m=119765235203392&w=2",
"source": "secalert@redhat.com"
},
{
"url": "http://osvdb.org/42633",
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/28095",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/archive/1/485037/100/0/threaded",
"source": "secalert@redhat.com"
},
{
"url": "http://www.squirrelmail.org/index.php",
"source": "secalert@redhat.com"
},
{
"url": "http://marc.info/?l=bugtraq&m=119765643909825&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=squirrelmail-devel&m=119756462212214&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=squirrelmail-devel&m=119765235203392&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/42633",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/28095",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/485037/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.squirrelmail.org/index.php",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse that introduces a PHP remote file inclusion vulnerability, which allows remote attackers to execute arbitrary code."
},
{
"lang": "es",
"value": "SquirrelMail versiones 1.4.11 y 1.4.12, distribuidas en sourceforge.net versiones anteriores a 20071213, se han modificado externamente para crear un Caballo de Troya que introduce una vulnerabilidad de inclusión remota de archivos PHP, que permite a los atacantes remotos ejecutar código arbitrario."
}
],
"lastModified": "2026-06-16T22:47:52.797",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "682BC5E2-F2C5-4B6F-8EF0-E05152BB9B12"
},
{
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ABC24558-B7C1-4DE7-BC24-AF092DF0DE97"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "The versions of SquirrelMail packages shipped in Red Hat Enterprise Linux 3, 4, and 5 were not affected by this issue. In addition, the Red Hat Security Response Team have verified that the malicious code is not part of released Red Hat Enterprise Linux squirrelmail packages.\n",
"lastModified": "2007-12-17T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "secalert@redhat.com"
}