5
CVSSv2

CVE-2007-2589

Published: 11/05/2007 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail 1.4.0 up to and including 1.4.9a allows remote malicious users to send e-mails from arbitrary users via certain data in the SRC attribute of an IMG element.

Vulnerable Product Search on Vulmon Subscribe to Product

squirrelmail squirrelmail 1.4.2

squirrelmail squirrelmail 1.4.6 rc1

squirrelmail squirrelmail 1.4.3 r3

squirrelmail squirrelmail 1.4.9a

squirrelmail squirrelmail 1.4.6

squirrelmail squirrelmail 1.4.7

squirrelmail squirrelmail 1.4.3 rc1

squirrelmail squirrelmail 1.4.4 rc1

squirrelmail squirrelmail 1.4.3

squirrelmail squirrelmail 1.4.1

squirrelmail squirrelmail 1.4.9

squirrelmail squirrelmail 1.4.8

squirrelmail squirrelmail 1.4.6 cvs

squirrelmail squirrelmail 1.4.0

squirrelmail squirrelmail 1.4.3a

squirrelmail squirrelmail 1.4.4

squirrelmail squirrelmail 1.4.3aa

squirrelmail squirrelmail 1.4.5