4.3
CVSSv2

CVE-2005-2095

Published: 13/07/2005 Updated: 11/10/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

options_identities.php in SquirrelMail 1.4.4 and previous versions uses the extract function to process the $_POST variable, which allows remote malicious users to modify or read the preferences of other users, conduct cross-site scripting XSS) attacks, and write arbitrary files.

Vulnerable Product Search on Vulmon Subscribe to Product

squirrelmail squirrelmail 1.0.5

squirrelmail squirrelmail 1.2.0

squirrelmail squirrelmail 1.2.5

squirrelmail squirrelmail 1.2.6

squirrelmail squirrelmail 1.4.3

squirrelmail squirrelmail 1.4.3_rc1

squirrelmail squirrelmail 1.2.11

squirrelmail squirrelmail 1.2.2

squirrelmail squirrelmail 1.4

squirrelmail squirrelmail 1.4.0

squirrelmail squirrelmail 1.2.1

squirrelmail squirrelmail 1.2.10

squirrelmail squirrelmail 1.2.7

squirrelmail squirrelmail 1.2.8

squirrelmail squirrelmail 1.2.9

squirrelmail squirrelmail 1.4.3a

squirrelmail squirrelmail 1.44

squirrelmail squirrelmail 1.0.4

squirrelmail squirrelmail 1.2.3

squirrelmail squirrelmail 1.2.4

squirrelmail squirrelmail 1.4.1

squirrelmail squirrelmail 1.4.2

Vendor Advisories

Synopsis squirrelmail security update Type/Severity Security Advisory: Moderate Topic An updated squirrelmail package that fixes two security issues is nowavailableThis update has been rated as having moderate security impact by the RedHat Security Response Team[Updated 04 Aug 2005]The previous SquirrelMa ...

Exploits

SquirrelMail Arbitrary Variable Overwrite Vendor: The SquirrelMail Project Team Product: SquirrelMail Version: <= 145-RC1 Website: wwwsquirrelmailorg/ BID: 14254 CVE: CVE-2005-2095 SECUNIA: 16058 PACKETSTORM: 38709 Description: SquirrelMail is a standards-based webmail package written in php It includes built-in pure PHP suppo ...