Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
squirrelmail vulnerabilities and exploits
(subscribe to this query)
10
CVSSv2
CVE-2004-0524
Buffer overflow in the chpasswd command in the Change_passwd plugin prior to 4.0, as used in SquirrelMail, allows local users to gain root privileges via a long user name.
2 EDB exploits
7.5
CVSSv2
CVE-2003-0990
The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote malicious users to execute commands via shell metacharacters in the "To:" field.
1 EDB exploit
5.8
CVSSv2
CVE-2003-0160
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail prior to 1.2.11 allow remote malicious users to inject arbitrary HTML code and steal information from a client's web browser.
Squirrelmail Squirrelmail
4.3
CVSSv2
CVE-2002-2086
Multiple cross-site scripting (XSS) vulnerabilities in magicHTML of SquirrelMail prior to 1.2.6 allow remote malicious users to inject arbitrary web script or HTML via (1) "<<script" in unspecified input fields or (2) a javascript: URL in the src attribute of an I...
Squirrelmail Squirrelmail 1.2.3
Squirrelmail Squirrelmail 1.2.4
Squirrelmail Squirrelmail 1.2.5
Squirrelmail Squirrelmail 1.2.0
Squirrelmail Squirrelmail 1.2.1
Squirrelmail Squirrelmail 1.2.2
1 Github repository
7.5
CVSSv2
CVE-2002-1648
Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail prior to 1.2.3 allows remote malicious users to send email as other users via an IMG URL with modified send_to and subject parameters.
Squirrelmail Squirrelmail 1.2.2
4.3
CVSSv2
CVE-2002-1649
Cross-site scripting (XSS) vulnerability in read_body.php in SquirrelMail prior to 1.2.3 allows remote malicious users to execute arbitrary Javascript via a javascript: URL in an IMG tag.
Squirrelmail Squirrelmail 1.2.2
7.5
CVSSv2
CVE-2002-1650
The spell checker plugin (check_me.mod.php) for SquirrelMail prior to 1.2.3 allows remote malicious users to execute arbitrary commands via a modified sqspell_command parameter.
Squirrelmail Squirrelmail 1.2.2
6.8
CVSSv2
CVE-2002-1341
Cross-site scripting (XSS) vulnerability in read_body.php for SquirrelMail 1.2.10, 1.2.9, and previous versions allows remote malicious users to insert script and HTML via the (1) mailbox and (2) passed_id parameters.
Squirrelmail Squirrelmail 1.2.9
Squirrelmail Squirrelmail 1.2.7
Squirrelmail Squirrelmail 1.2.8
Squirrelmail Squirrelmail 1.2.10
Squirrelmail Squirrelmail 1.2.6
4.3
CVSSv2
CVE-2002-1276
An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving it open to cross-site scripting attacks.
Squirrelmail Squirrelmail 1.2.8
7.5
CVSSv2
CVE-2002-1131
Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and previous versions allows remote malicious users to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php.
Squirrelmail Squirrelmail
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
NEXT »