6.8
CVSSv2

CVE-2009-2964

Published: 25/08/2009 Updated: 19/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.19 and previous versions, and NaSMail prior to 1.7, allow remote malicious users to hijack the authentication of unspecified victims via features such as send message and change preferences, related to (1) functions/mailbox_display.php, (2) src/addrbook_search_html.php, (3) src/addressbook.php, (4) src/compose.php, (5) src/folders.php, (6) src/folders_create.php, (7) src/folders_delete.php, (8) src/folders_rename_do.php, (9) src/folders_rename_getname.php, (10) src/folders_subscribe.php, (11) src/move_messages.php, (12) src/options.php, (13) src/options_highlight.php, (14) src/options_identities.php, (15) src/options_order.php, (16) src/search.php, and (17) src/vcard.php.

Vulnerable Product Search on Vulmon Subscribe to Product

squirrelmail squirrelmail 1.4.7

squirrelmail squirrelmail 1.4.6_rc1

squirrelmail squirrelmail 1.4.4

squirrelmail squirrelmail 1.4.3aa

squirrelmail squirrelmail 1.4_rc1

squirrelmail squirrelmail 1.4

squirrelmail squirrelmail 1.4.6_cvs

squirrelmail squirrelmail 1.4.6

squirrelmail squirrelmail 1.4.3a

squirrelmail squirrelmail 1.4.3_rc1

squirrelmail squirrelmail 1.4.2-r4

squirrelmail squirrelmail 1.4.2-r3

squirrelmail squirrelmail 1.4.15

squirrelmail squirrelmail 1.4.12

squirrelmail squirrelmail 1.4.0

squirrelmail squirrelmail 1.2.9

squirrelmail squirrelmail 1.2.8

squirrelmail squirrelmail 1.2.11

squirrelmail squirrelmail 1.2.10

squirrelmail squirrelmail 1.1.2

squirrelmail squirrelmail 1.1.1

squirrelmail squirrelmail 1.0.4

squirrelmail squirrelmail 1.0.3

squirrelmail squirrelmail 1.4.13

squirrelmail squirrelmail

squirrelmail squirrelmail 1.4.3

squirrelmail squirrelmail 1.4.2-r5

squirrelmail squirrelmail 1.4.16

squirrelmail squirrelmail 1.4.15_rc1

squirrelmail squirrelmail 1.4.0_rc2a

squirrelmail squirrelmail 1.4.0_rc1

squirrelmail squirrelmail 1.3.1

squirrelmail squirrelmail 1.3.0

squirrelmail squirrelmail 1.2.4

squirrelmail squirrelmail 1.2.3

squirrelmail squirrelmail 1.2.2

squirrelmail squirrelmail 1.2

squirrelmail squirrelmail 1.1.3

squirrelmail squirrelmail 1.0.6

squirrelmail squirrelmail 1.0.5

squirrelmail squirrelmail 1.4.18

squirrelmail squirrelmail 1.4.15rc1

squirrelmail squirrelmail 1.4.8.4fc6

squirrelmail squirrelmail 1.4.8

squirrelmail squirrelmail 1.4.4_rc1

squirrelmail squirrelmail 1.4.2

squirrelmail squirrelmail 1.4.17

squirrelmail squirrelmail 1.4.10

squirrelmail squirrelmail 1.4.1

squirrelmail squirrelmail 1.3.2

squirrelmail squirrelmail 1.2.6

squirrelmail squirrelmail 1.2.5

squirrelmail squirrelmail 1.2.0

squirrelmail squirrelmail 1.0pre2

squirrelmail squirrelmail 1.0pre1

squirrelmail squirrelmail 1.0

squirrelmail squirrelmail 0.1.2

squirrelmail squirrelmail 0.1.1

squirrelmail squirrelmail 1.4.9a

squirrelmail squirrelmail 1.4.9

squirrelmail squirrelmail 1.4.5_rc1

squirrelmail squirrelmail 1.4.5

squirrelmail squirrelmail 1.4.3_r3

squirrelmail squirrelmail 1.4.2-r2

squirrelmail squirrelmail 1.4.2-r1

squirrelmail squirrelmail 1.4.11

squirrelmail squirrelmail 1.4.10a

squirrelmail squirrelmail 1.4.0-r1

squirrelmail squirrelmail 1.2.7

squirrelmail squirrelmail 1.2.6-rc1

squirrelmail squirrelmail 1.2.1

squirrelmail squirrelmail 1.2.0_rc3

squirrelmail squirrelmail 1.1.0

squirrelmail squirrelmail 1.0pre3

squirrelmail squirrelmail 1.0.2

squirrelmail squirrelmail 1.0.1

Vendor Advisories

Debian Bug report logs - #543818 CVE-2009-2964: Multiple cross-site request forgery (CSRF) vulnerabilities Package: squirrelmail; Maintainer for squirrelmail is Jeroen van Wolffelaar <jeroen@wolffelaarnl>; Source for squirrelmail is src:squirrelmail (PTS, buildd, popcon) Reported by: Giuseppe Iuculano <giuseppe@iuculano ...
SquirrelMail, a webmail application, does not employ a user-specific token for webforms This allows a remote attacker to perform a Cross Site Request Forgery (CSRF) attack The attacker may hijack the authentication of unspecified victims and send messages or change user preferences among other actions, by tricking the victim into following a link ...

References

CWE-352http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&revision=13818http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/doc/ChangeLog?revision=13818&view=markup&pathrev=13818https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00954.htmlhttp://www.squirrelmail.org/security/issue/2009-08-12https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00927.htmlhttp://www.vupen.com/english/advisories/2009/2262https://bugzilla.redhat.com/show_bug.cgi?id=517312http://www.osvdb.org/57001http://secunia.com/advisories/36363http://secunia.com/advisories/34627http://www.mandriva.com/security/advisories?name=MDVSA-2009:222http://www.securityfocus.com/bid/36196http://secunia.com/advisories/37415http://www.vupen.com/english/advisories/2009/3315http://osvdb.org/60469https://gna.org/forum/forum.php?forum_id=2146http://download.gna.org/nasmail/nasmail-1.7.ziphttp://lists.apple.com/archives/security-announce/2010//Jun/msg00001.htmlhttp://secunia.com/advisories/40220http://www.vupen.com/english/advisories/2010/1481http://support.apple.com/kb/HT4188http://www.vupen.com/english/advisories/2010/2080http://www.debian.org/security/2010/dsa-2091http://secunia.com/advisories/40964http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543818http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002207.htmlhttp://jvn.jp/en/jp/JVN30881447/index.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/52406https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10668https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543818https://nvd.nist.govhttps://www.debian.org/security/./dsa-2091