6.8
CVSSv2

CVE-2004-0520

Published: 18/08/2004 Updated: 11/10/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail prior to 1.4.3 allows remote malicious users to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.

Vulnerable Product Search on Vulmon Subscribe to Product

open webmail open webmail 2.30

squirrelmail squirrelmail 1.2.11

squirrelmail squirrelmail 1.2.2

squirrelmail squirrelmail 1.2.9

squirrelmail squirrelmail 1.4

sgi propack 3.0

squirrelmail squirrelmail 1.2.0

squirrelmail squirrelmail 1.2.5

squirrelmail squirrelmail 1.2.6

squirrelmail squirrelmail 1.4.3_rc1

squirrelmail squirrelmail 1.5_dev

squirrelmail squirrelmail 1.2.1

squirrelmail squirrelmail 1.2.10

squirrelmail squirrelmail 1.2.7

squirrelmail squirrelmail 1.2.8

open webmail open webmail 2.31

open webmail open webmail 2.32

squirrelmail squirrelmail 1.2.3

squirrelmail squirrelmail 1.2.4

squirrelmail squirrelmail 1.4.1

squirrelmail squirrelmail 1.4.2

Vendor Advisories

Synopsis squirrelmail security update Type/Severity Security Advisory: Important Topic An updated SquirrelMail package that fixes several security vulnerabilitiesis now available Description SquirrelMail is a webmail package written in PHP Multiplevulnerabilities have been found which af ...

Exploits

source: wwwsecurityfocuscom/bid/10439/info SquirrelMail is reported to be prone to an email header HTML injection vulnerability This issue is due to a failure of the application to properly sanitize user-supplied email header strings An attacker can exploit this issue to gain access to an unsuspecting user's cookie based authentication ...