The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation54 reference(s) from NVD