CVE-2002-1341: XSS
Cross-site scripting (XSS) vulnerability in readbody.php for SquirrelMail 1.2.10, 1.2.9, and earlier allows remote attackers to insert script and HTML via the (1) mailbox and (2) passedid parameters.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1341?
CVE-2002-1341 is classified as a medium severity vulnerability due to its potential for user exploitation through cross-site scripting.
How do I fix CVE-2002-1341?
To fix CVE-2002-1341, it is recommended to upgrade SquirrelMail to the latest version that patches this vulnerability.
What software versions are affected by CVE-2002-1341?
SquirrelMail versions 1.2.10, 1.2.9, 1.2.8, 1.2.7, and 1.2.6 are affected by CVE-2002-1341.
What type of attack does CVE-2002-1341 enable?
CVE-2002-1341 enables attackers to perform cross-site scripting (XSS) attacks through manipulating mailbox and passed_id parameters.
How can I test for CVE-2002-1341?
To test for CVE-2002-1341, you can try injecting script tags into relevant fields in the affected SquirrelMail web application.