5
CVSSv2

CVE-2007-2589

Published: 11/05/2007 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail 1.4.0 up to and including 1.4.9a allows remote malicious users to send e-mails from arbitrary users via certain data in the SRC attribute of an IMG element.

Vulnerable Product Search on Vulmon Subscribe to Product

squirrelmail squirrelmail 1.4.2

squirrelmail squirrelmail 1.4.3

squirrelmail squirrelmail 1.4.5

squirrelmail squirrelmail 1.4.6

squirrelmail squirrelmail 1.4.3_r3

squirrelmail squirrelmail 1.4.3_rc1

squirrelmail squirrelmail 1.4.6_cvs

squirrelmail squirrelmail 1.4.6_rc1

squirrelmail squirrelmail 1.4.3a

squirrelmail squirrelmail 1.4.3aa

squirrelmail squirrelmail 1.4.7

squirrelmail squirrelmail 1.4.8

squirrelmail squirrelmail 1.4.0

squirrelmail squirrelmail 1.4.1

squirrelmail squirrelmail 1.4.4

squirrelmail squirrelmail 1.4.4_rc1

squirrelmail squirrelmail 1.4.9

squirrelmail squirrelmail 1.4.9a