5
CVSSv2

CVE-2002-1132

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

SquirrelMail 1.2.7 and previous versions allows remote malicious users to determine the absolute pathname of the options.php script via a malformed optpage file argument, which generates an error message when the file cannot be included in the script.

Vulnerable Product Search on Vulmon Subscribe to Product

squirrelmail squirrelmail

Vendor Advisories

Several cross site scripting vulnerabilities have been found in squirrelmail, a feature-rich webmail package written in PHP4 The Common Vulnerabilities and Exposures (CVE) project identified the following vulnerabilities: CAN-2002-1131: User input is not always sanitized so execution of arbitrary code on a client computer is possible This ca ...