Mandriva Linux Security Advisory MDKSA-2006-101- A PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plugins array parameter.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/47559/MDKSA-2006-101.txt
Source: https://packetstormsecurity.com/files/47559/Mandriva-Linux-Security-Advisory-2006.101.html

