Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail prior to 1.4.3 allows remote malicious users to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
open webmail open webmail 2.30 |
||
squirrelmail squirrelmail 1.2.11 |
||
squirrelmail squirrelmail 1.2.2 |
||
squirrelmail squirrelmail 1.2.9 |
||
squirrelmail squirrelmail 1.4 |
||
sgi propack 3.0 |
||
squirrelmail squirrelmail 1.2.0 |
||
squirrelmail squirrelmail 1.2.5 |
||
squirrelmail squirrelmail 1.2.6 |
||
squirrelmail squirrelmail 1.4.3_rc1 |
||
squirrelmail squirrelmail 1.5_dev |
||
squirrelmail squirrelmail 1.2.1 |
||
squirrelmail squirrelmail 1.2.10 |
||
squirrelmail squirrelmail 1.2.7 |
||
squirrelmail squirrelmail 1.2.8 |
||
open webmail open webmail 2.31 |
||
open webmail open webmail 2.32 |
||
squirrelmail squirrelmail 1.2.3 |
||
squirrelmail squirrelmail 1.2.4 |
||
squirrelmail squirrelmail 1.4.1 |
||
squirrelmail squirrelmail 1.4.2 |