4.3
CVSSv2

CVE-2005-0104

Published: 29/01/2005 Updated: 11/10/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail prior to 1.4.4 allows remote malicious users to inject arbitrary web script or HTML via certain integer variables.

Vulnerable Product Search on Vulmon Subscribe to Product

squirrelmail squirrelmail 1.0.4

squirrelmail squirrelmail 1.2.3

squirrelmail squirrelmail 1.2.1

squirrelmail squirrelmail 1.2.10

squirrelmail squirrelmail 1.2.7

squirrelmail squirrelmail 1.2.8

squirrelmail squirrelmail 1.2.9

squirrelmail squirrelmail 1.4.3a

squirrelmail squirrelmail 1.44

squirrelmail squirrelmail 1.0.5

squirrelmail squirrelmail 1.2.0

squirrelmail squirrelmail 1.2.5

squirrelmail squirrelmail 1.2.6

squirrelmail squirrelmail 1.4.3

squirrelmail squirrelmail 1.4.3_rc1

squirrelmail squirrelmail 1.2.4

squirrelmail squirrelmail 1.4.1

squirrelmail squirrelmail 1.4.2

squirrelmail squirrelmail 1.2.11

squirrelmail squirrelmail 1.2.2

squirrelmail squirrelmail 1.4

squirrelmail squirrelmail 1.4.0

Vendor Advisories

Synopsis squirrelmail security update Type/Severity Security Advisory: Low Topic An updated Squirrelmail package that fixes several security issues is nowavailable for Red Hat Enterprise Linux 3 Description SquirrelMail is a standards-based webmail package written in PHP4Jimmy Conner disc ...
Synopsis squirrelmail security update Type/Severity Security Advisory: Moderate Topic An updated Squirrelmail package that fixes several security issues is nowavailable for Red Hat Enterprise Linux 4This update has been rated as having moderate security impact by the Red HatSecurity Response Team ...
Andrew Archibald discovered that the last update to squirrelmail which was intended to fix several problems caused a regression which got exposed when the user hits a session timeout  For completeness below is the original advisory text: Several vulnerabilities have been discovered in Squirrelmail, a commonly used webmail system The Common Vuln ...