PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."
http://www.kb.cert.org/vuls/id/203214
http://www.debian.org/security/2005/dsa-662
http://secunia.com/advisories/14096
http://ftp.debian.org/debian/dists/stable-proposed-updates/squirrelmail_1.2.6-2_i386.changes