AOH :: HP Unsorted S :: B06-2497.HTM

Socketmail <= 2.2.6 - remote file include vulnerability
Socketmail <= 2.2.6 - Remote File Include Vulnerability
Socketmail <= 2.2.6 - Remote File Include Vulnerability

[MajorSecurity]Socketmail <= 2.2.6 - Remote File Include Vulnerability

Software: Socketmail

Version: <=2.2.6

Type: Remote File Include Vulnerability

Date: May, 25th 2006

Vendor: Creative Digital Resources


Risc: High



Affected Products:

Socketmail Lite 2.2.6 and prior
Socketmail  Pro 2.2.6 and prior


SocketMail is a powerful, scalable and fully customisable e-mail solution.
Ideal messaging solution for sizes web site and enterprises.


register_globals = On
magic_quotes = On


Input passed to the "site_path" parameter in "index.php" and "inc-common.php" is not
properly verified, before it is used to include files.
This can be exploited to execute arbitrary code by including files from external resources.


Edit the source code to ensure that input is properly sanitised.
Set "register_globals" to "Off".


Post data:


The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2015 AOH
We do not send spam. If you have received spam bearing an email address, please forward it with full headers to