First published: Wed Mar 26 2003(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SquirrelMail | <=1.2.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2003-0160 is considered to be medium due to potential exploitation via cross-site scripting.
To fix CVE-2003-0160, upgrade SquirrelMail to version 1.2.11 or later.
All versions of SquirrelMail before version 1.2.11 are affected by CVE-2003-0160.
CVE-2003-0160 is a cross-site scripting (XSS) vulnerability.
Attackers can use CVE-2003-0160 to inject arbitrary HTML code and potentially steal sensitive information from users' web browsers.