← Vulnerability feed

Vulnerability record · CVE-2006-2842 · published 6 June 2006

CVE-2006-2842: SquirrelMail plugin.php remote file inclusion via plugins array

Squirrelmail · Squirrelmail

SquirrelMail 1.4.6 and earlier contains a remote file inclusion flaw in functions/plugin.php: when register_globals is enabled and magic_quotes_gpc is disabled, the plugins array parameter can be set to a remote URL. This lets an attacker cause the application to include and execute arbitrary PHP code. The issue is disputed by third parties who note SquirrelMail warns administrators about register_globals, but the original developer published a security advisory, so real-world exposure depends on that misconfiguration.

7.5 CVSS 2.0 High EPSS 47% · top 1.2%
7.5CVSS 2.0 base score
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
40References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plugins array parameter. NOTE: this issue has been disputed by third parties, who state that Squirrelmail provides prominent warnings to the administrator when register_globals is enabled. Since the varieties of administrator negligence are uncountable, perhaps this type of issue should not be included in CVE. However, the original developer has posted a security advisory, so there might be relevant real-world environments under which this vulnerability is applicable

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 2.0 base score is 7.5 (HIGH) with network reachability and no authentication, and public exploit references exist, though exploitation requires specific PHP misconfiguration.

What it is

SquirrelMail 1.4.6 and earlier contains a remote file inclusion flaw in functions/plugin.php: when register_globals is enabled and magic_quotes_gpc is disabled, the plugins array parameter can be set to a remote URL. This lets an attacker cause the application to include and execute arbitrary PHP code. The issue is disputed by third parties who note SquirrelMail warns administrators about register_globals, but the original developer published a security advisory, so real-world exposure depends on that misconfiguration.

Impact

An unauthenticated attacker can execute arbitrary PHP code on the server, leading to full compromise of the web application and potentially the host.

Attack surface

Reachable over the network through HTTP requests to the affected SquirrelMail installation; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N. Exploitation only works when register_globals is enabled and magic_quotes_gpc is disabled.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.47196, 98.8th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade SquirrelMail to a version containing the fix referenced in the vendor advisory and patch links.
  • Disable register_globals in PHP configuration and ensure magic_quotes_gpc is not relied upon for protection.
  • Apply vendor or distribution patches (Red Hat, Mandriva, Novell, SGI, Apple advisories) where SquirrelMail is packaged.
  • Restrict outbound network access from the web server to limit remote file inclusion fetches.
  • Review and harden PHP include paths and disable allow_url_include/allow_url_fopen where feasible.

Detection

  • Monitor web logs for requests to functions/plugin.php with a plugins parameter containing a URL or remote host.
  • Alert on PHP include or file access events referencing external HTTP/FTP URLs from the SquirrelMail process.
  • Search for unexpected PHP files or web shells written under the SquirrelMail web root.
  • Audit PHP configuration for register_globals enabled on hosts running SquirrelMail.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc
http://docs.info.apple.com/article.html?artnum=306172
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html
http://secunia.com/advisories/20406 PatchVendor Advisory
http://secunia.com/advisories/20931
http://secunia.com/advisories/21159
http://secunia.com/advisories/21262
http://secunia.com/advisories/26235
http://securitytracker.com/id?1016209
http://squirrelmail.cvs.sourceforge.net/squirrelmail/squirrelmail/functions/global.php?r1=1.27.2.16&r2=1.27.2.17&view=pa Patch
http://www.mandriva.com/security/advisories?name=MDKSA-2006:101
http://www.novell.com/linux/security/advisories/2006_17_sr.html
http://www.redhat.com/support/errata/RHSA-2006-0547.html
http://www.securityfocus.com/archive/1/435605/100/0/threaded
http://www.securityfocus.com/bid/18231 Exploit
http://www.securityfocus.com/bid/25159
http://www.squirrelmail.org/security/issue/2006-06-01 Patch
http://www.vupen.com/english/advisories/2006/2101
http://www.vupen.com/english/advisories/2007/2732
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11670
ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc
http://docs.info.apple.com/article.html?artnum=306172
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html
http://secunia.com/advisories/20406 PatchVendor Advisory
http://secunia.com/advisories/20931
http://secunia.com/advisories/21159
http://secunia.com/advisories/21262
http://secunia.com/advisories/26235
http://securitytracker.com/id?1016209
http://squirrelmail.cvs.sourceforge.net/squirrelmail/squirrelmail/functions/global.php?r1=1.27.2.16&r2=1.27.2.17&view=pa Patch
http://www.mandriva.com/security/advisories?name=MDKSA-2006:101
http://www.novell.com/linux/security/advisories/2006_17_sr.html
http://www.redhat.com/support/errata/RHSA-2006-0547.html
http://www.securityfocus.com/archive/1/435605/100/0/threaded
http://www.securityfocus.com/bid/18231 Exploit
http://www.securityfocus.com/bid/25159
http://www.squirrelmail.org/security/issue/2006-06-01 Patch
http://www.vupen.com/english/advisories/2006/2101
http://www.vupen.com/english/advisories/2007/2732
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11670

Track CVE-2006-2842 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0521Sgi propack vulnerabilitySQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, pro…EPSS 3.2%10.0CVE-2002-0516Squirrelmail vulnerabilitySquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie.EPSS 11%9.8CVE-2020-14932Squirrelmail deserialization of untrusted data vulnerabilitycompose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request. This is related to mailto.…EPSS 1.4%8.8CVE-2020-14933Squirrelmail deserialization of untrusted data vulnerabilitycompose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor dispute…EPSS 1.4%8.8CVE-2018-8741Squirrelmail path traversal vulnerabilityA directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting serve…EPSS 4.2%8.8CVE-2017-7692Squirrelmail improper input validation vulnerabilitySquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mis…EPSS 32%7.5CVE-2007-3636Squirrelmail gpg plugin vulnerabilityMultiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via unspecif…EPSS 3.1%7.5CVE-2007-2631Squirrelmail vulnerabilityCross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actions as arb…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2006-2842), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.