6.8
CVSSv2

CVE-2011-2753

Published: 17/07/2011 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.21 and previous versions allow remote malicious users to hijack the authentication of unspecified victims via vectors involving (1) the empty trash implementation and (2) the Index Order (aka options_order) page, a different issue than CVE-2010-4555.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

squirrelmail squirrelmail 0.1

squirrelmail squirrelmail 0.4

squirrelmail squirrelmail 1.4.17

squirrelmail squirrelmail 1.4.0

squirrelmail squirrelmail 1.4.19

squirrelmail squirrelmail 1.4.10

squirrelmail squirrelmail 1.3.0

squirrelmail squirrelmail 1.0pre1

squirrelmail squirrelmail 1.0pre2

squirrelmail squirrelmail 1.0pre3

squirrelmail squirrelmail 0.5pre2

squirrelmail squirrelmail 0.5

squirrelmail squirrelmail 1.4.11

squirrelmail squirrelmail 1.0.5

squirrelmail squirrelmail 1.4.2-r2

squirrelmail squirrelmail 1.4.2-r5

squirrelmail squirrelmail 1.4.2-r4

squirrelmail squirrelmail 1.4.6

squirrelmail squirrelmail 1.4.5

squirrelmail squirrelmail 1.4.10a

squirrelmail squirrelmail 1.2.4

squirrelmail squirrelmail 0.3pre2

squirrelmail squirrelmail 0.3pre1

squirrelmail squirrelmail 1.4.3

squirrelmail squirrelmail 1.4.4

squirrelmail squirrelmail 1.4.16

squirrelmail squirrelmail 1.1.2

squirrelmail squirrelmail 1.1.3

squirrelmail squirrelmail 1.0.6

squirrelmail squirrelmail 0.5pre1

squirrelmail squirrelmail 1.4.20

squirrelmail squirrelmail 1.4.12

squirrelmail squirrelmail 1.4.2-r1

squirrelmail squirrelmail 1.4.2-r3

squirrelmail squirrelmail 1.4.7

squirrelmail squirrelmail 1.4.6_cvs

squirrelmail squirrelmail 1.4.2

squirrelmail squirrelmail 1.4.1

squirrelmail squirrelmail 1.2.5

squirrelmail squirrelmail 1.2.6

squirrelmail squirrelmail 1.2.3

squirrelmail squirrelmail 1.4.9a

squirrelmail squirrelmail

squirrelmail squirrelmail 0.3.1

squirrelmail squirrelmail 0.3

squirrelmail squirrelmail 1.4.15

squirrelmail squirrelmail 1.4.15rc1

squirrelmail squirrelmail 1.4.18

squirrelmail squirrelmail 1.1.0

squirrelmail squirrelmail 1.1.1

squirrelmail squirrelmail 1.0.2

squirrelmail squirrelmail 1.0.3

squirrelmail squirrelmail 1.2

squirrelmail squirrelmail 1.4.0-r1

squirrelmail squirrelmail 1.4.8.4fc6

squirrelmail squirrelmail 1.4.8

squirrelmail squirrelmail 1.4.3a

squirrelmail squirrelmail 1.2.7

squirrelmail squirrelmail 1.2.8

squirrelmail squirrelmail 1.2.10

squirrelmail squirrelmail 1.4

squirrelmail squirrelmail 1.2.11

squirrelmail squirrelmail 0.2.1

squirrelmail squirrelmail 0.2

squirrelmail squirrelmail 0.1.2

squirrelmail squirrelmail 0.1.1

squirrelmail squirrelmail 1.4.13

squirrelmail squirrelmail 1.2.0

squirrelmail squirrelmail 1.3.2

squirrelmail squirrelmail 1.3.1

squirrelmail squirrelmail 1.0

squirrelmail squirrelmail 1.0.1

squirrelmail squirrelmail 0.4pre1

squirrelmail squirrelmail 0.4pre2

squirrelmail squirrelmail 1.0.4

squirrelmail squirrelmail 1.4.9

squirrelmail squirrelmail 1.4.3aa

squirrelmail squirrelmail 1.2.9

squirrelmail squirrelmail 1.2.2

squirrelmail squirrelmail 1.2.1

Vendor Advisories

Synopsis Moderate: squirrelmail security update Type/Severity Security Advisory: Moderate Topic An updated squirrelmail package that fixes several security issues is nowavailable for Red Hat Enterprise Linux 4 and 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact ...