Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
squirrelmail squirrelmail vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2002-1132
SquirrelMail 1.2.7 and previous versions allows remote malicious users to determine the absolute pathname of the options.php script via a malformed optpage file argument, which generates an error message when the file cannot be included in the script.
Squirrelmail Squirrelmail
4.6
CVSSv2
CVE-2006-0331
Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments.
Thiago Melo De Paula Change Passwd 3.1
1 EDB exploit
4.3
CVSSv2
CVE-2019-12970
XSS exists in SquirrelMail up to and including 1.4.22 and 1.5.x up to and including 1.5.2. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the appli...
Squirrelmail Squirrelmail
1 Github repository
4.3
CVSSv2
CVE-2018-14950
The mail message display page in SquirrelMail up to and including 1.4.22 has XSS via a "<svg><a xlink:href=" attack.
Squirrelmail Squirrelmail
4.3
CVSSv2
CVE-2018-14951
The mail message display page in SquirrelMail up to and including 1.4.22 has XSS via a "<form action='data:text" attack.
Squirrelmail Squirrelmail
4.3
CVSSv2
CVE-2018-14953
The mail message display page in SquirrelMail up to and including 1.4.22 has XSS via a "<math xlink:href=" attack.
Squirrelmail Squirrelmail
4.3
CVSSv2
CVE-2018-14954
The mail message display page in SquirrelMail up to and including 1.4.22 has XSS via the formaction attribute.
Squirrelmail Squirrelmail
4.3
CVSSv2
CVE-2018-14952
The mail message display page in SquirrelMail up to and including 1.4.22 has XSS via a "<math><maction xlink:href=" attack.
Squirrelmail Squirrelmail
4.3
CVSSv2
CVE-2018-14955
The mail message display page in SquirrelMail up to and including 1.4.22 has XSS via SVG animations (animate to attribute).
Squirrelmail Squirrelmail
4.3
CVSSv2
CVE-2012-0323
Cross-site scripting (XSS) vulnerability in the Autocomplete plugin prior to 3.0 for SquirrelMail allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Paul Lesniewsk Autocomplete 2.0
Paul Lesniewsk Autocomplete 1.3
Paul Lesniewsk Autocomplete 1.2
Paul Lesniewsk Autocomplete 1.1
Paul Lesniewsk Autocomplete 1.0
Paul Lesniewsk Autocomplete
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »