6.8
CVSSv2

CVE-2004-0519

Published: 18/08/2004 Updated: 11/10/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote malicious users to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.

Vulnerable Product Search on Vulmon Subscribe to Product

squirrelmail squirrelmail 1.0.4

squirrelmail squirrelmail 1.0.5

squirrelmail squirrelmail 1.2.4

squirrelmail squirrelmail 1.2.5

squirrelmail squirrelmail 1.2.10

squirrelmail squirrelmail 1.2.11

squirrelmail squirrelmail 1.2.8

squirrelmail squirrelmail 1.2.9

sgi propack 3.0

squirrelmail squirrelmail 1.2.2

squirrelmail squirrelmail 1.2.3

squirrelmail squirrelmail 1.4

squirrelmail squirrelmail 1.4.1

squirrelmail squirrelmail 1.4.2

squirrelmail squirrelmail 1.2.0

squirrelmail squirrelmail 1.2.1

squirrelmail squirrelmail 1.2.6

squirrelmail squirrelmail 1.2.7

Vendor Advisories

Synopsis squirrelmail security update Type/Severity Security Advisory: Important Topic An updated SquirrelMail package that fixes several security vulnerabilitiesis now available Description SquirrelMail is a webmail package written in PHP Multiplevulnerabilities have been found which af ...

Exploits

source: wwwsecurityfocuscom/bid/10246/info It has been reported that SquirrelMail is affected by a cross-site scripting vulnerability in the handling of folder name displays This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamic web content This issue may allow for th ...