viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the cert parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/19242
http://www.squirrelmail.org/plugin_view.php?id=54
http://www.kb.cert.org/vuls/id/502328
http://www.idefense.com/application/poi/display?id=191&type=vulnerabilities&flashstatus=false