4.3
CVSSv2

CVE-2002-1276

Published: 29/11/2002 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving it open to cross-site scripting attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

squirrelmail squirrelmail 1.2.8

Vendor Advisories

Several cross site scripting vulnerabilities have been found in squirrelmail, a feature-rich webmail package written in PHP4 The Common Vulnerabilities and Exposures (CVE) project identified the following vulnerabilities: CAN-2002-1131: User input is not always sanitized so execution of arbitrary code on a client computer is possible This ca ...