PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[basedir] parameter. A solution/patch has been released for these vulnerabilities:
CVE-2007-2826
CVE-2007-3058
https://sourceforge.net/projects/madirishwebmail/
https://sourceforge.net/project/shownotes.phpgroup_id101727&release_id517013
Publication date: Wed, 23 May 2007 02:30:00 +0000