7.5
CVSSv2

CVE-2005-1308

Published: 15/04/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SqWebMail allows remote malicious users to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML.

Vulnerable Product Search on Vulmon Subscribe to Product

inter7 sqwebmail 4.0.4_2004-05-24

inter7 sqwebmail 4.0.5

inter7 sqwebmail 3.5.2

inter7 sqwebmail 3.6.0

inter7 sqwebmail 3.4.1

inter7 sqwebmail 3.5.0

inter7 sqwebmail 3.5.1

inter7 sqwebmail 3.5.3

inter7 sqwebmail 3.6.1

Exploits

source: wwwsecurityfocuscom/bid/13374/info SQWebmail is prone to a HTTP response splitting vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input A remote attacker may exploit this vulnerability to influence or misrepresent how Web content is served, cached or interpreted This could ai ...