6.8
CVSSv2

CVE-2004-1036

Published: 01/03/2005 Updated: 11/10/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the decoding of encoded text in certain headers in mime.php for SquirrelMail 1.4.3a and previous versions, and 1.5.1-cvs prior to 23rd October 2004, allows remote malicious users to execute arbitrary web script or HTML.

Vulnerable Product Search on Vulmon Subscribe to Product

squirrelmail squirrelmail 1.2.11

squirrelmail squirrelmail 1.2.2

squirrelmail squirrelmail 1.2.9

squirrelmail squirrelmail 1.4

squirrelmail squirrelmail 1.2.1

squirrelmail squirrelmail 1.2.10

squirrelmail squirrelmail 1.2.7

squirrelmail squirrelmail 1.2.8

squirrelmail squirrelmail 1.5_dev

squirrelmail squirrelmail 1.0.5

squirrelmail squirrelmail 1.2

squirrelmail squirrelmail 1.2.5

squirrelmail squirrelmail 1.2.6

squirrelmail squirrelmail 1.4.3_rc1

squirrelmail squirrelmail 1.4.3a

squirrelmail squirrelmail 1.0.4

squirrelmail squirrelmail 1.2.3

squirrelmail squirrelmail 1.2.4

squirrelmail squirrelmail 1.4.1

squirrelmail squirrelmail 1.4.2

squirrelmail squirrelmail 1.4.3

gentoo linux

Vendor Advisories

Synopsis squirrelmail security update Type/Severity Security Advisory: Moderate Topic An updated SquirrelMail package that fixes a cross-site scriptingvulnerability is now available Description SquirrelMail is a webmail package written in PHPA cross-site scripting bug has been found in Sq ...