First published: Tue May 12 2009(Updated: )
A, From SquirrelMail vulnerability report (<a href="http://www.squirrelmail.org/security/issue/2009-05-08">http://www.squirrelmail.org/security/issue/2009-05-08</a>): Two issues were fixed that both allowed an attacker to run arbitrary script (XSS) on most any SquirrelMail page by getting the user to click on specially crafted SquirrelMail links. Credits: Niels Teusink and Christian Balzer Patch: <a href="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&revision=13670">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&revision=13670</a> B, From SquirrelMail vulnerability report: (<a href="http://www.squirrelmail.org/security/issue/2009-05-09">http://www.squirrelmail.org/security/issue/2009-05-09</a>): An issue was fixed wherein input to the contrib/decrypt_headers.php script was not sanitized and allowed arbitrary script execution upon submission of certain values. Credits: Niels Teusink Patch: <a href="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&revision=13672">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&revision=13672</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Squirrelmail Squirrelmail | =1.3.1 | |
Squirrelmail Squirrelmail | =0.4 | |
Squirrelmail Squirrelmail | =1.0.6 | |
Squirrelmail Squirrelmail | =1.0.5 | |
Squirrelmail Squirrelmail | =0.3 | |
Squirrelmail Squirrelmail | =0.4pre2 | |
Squirrelmail Squirrelmail | =1.1.0 | |
Squirrelmail Squirrelmail | =1.0pre2 | |
Squirrelmail Squirrelmail | =0.3.1 | |
Squirrelmail Squirrelmail | =0.1.2 | |
Squirrelmail Squirrelmail | =1.2.7 | |
Squirrelmail Squirrelmail | =1.0.1 | |
Squirrelmail Squirrelmail | =0.2.1 | |
Squirrelmail Squirrelmail | =1.4.12 | |
Squirrelmail Squirrelmail | =1.2.0 | |
Squirrelmail Squirrelmail | =1.2.9 | |
Squirrelmail Squirrelmail | =0.1 | |
Squirrelmail Squirrelmail | =1.4.15 | |
Squirrelmail Squirrelmail | =1.2.2 | |
Squirrelmail Squirrelmail | =0.5pre2 | |
Squirrelmail Squirrelmail | =1.1.1 | |
Squirrelmail Squirrelmail | =1.4.16 | |
Squirrelmail Squirrelmail | =1.2.0_rc3 | |
Squirrelmail Squirrelmail | =1.1.2 | |
Squirrelmail Squirrelmail | =1.4.15_rc1 | |
Squirrelmail Squirrelmail | ||
Squirrelmail Squirrelmail | =0.3pre2 | |
Squirrelmail Squirrelmail | =0.1.1 | |
Squirrelmail Squirrelmail | =1.3.2 | |
Squirrelmail Squirrelmail | =1.2.1 | |
Squirrelmail Squirrelmail | =1.4.1 | |
Squirrelmail Squirrelmail | =1.2 | |
Squirrelmail Squirrelmail | =1.4.0_rc2a | |
Squirrelmail Squirrelmail | =1.4.0_rc1 | |
Squirrelmail Squirrelmail | =1.4.0 | |
Squirrelmail Squirrelmail | =1.4 | |
Squirrelmail Squirrelmail | =1.1.3 | |
Squirrelmail Squirrelmail | =1.2.4 | |
Squirrelmail Squirrelmail | =0.5pre1 | |
Squirrelmail Squirrelmail | =1.2.3 | |
Squirrelmail Squirrelmail | =1.4.10 | |
Squirrelmail Squirrelmail | =1.0.2 | |
Squirrelmail Squirrelmail | =1.0.4 | |
Squirrelmail Squirrelmail | =1.0pre1 | |
Squirrelmail Squirrelmail | =1.2.6 | |
Squirrelmail Squirrelmail | =1.4.10a | |
Squirrelmail Squirrelmail | =0.3pre1 | |
Squirrelmail Squirrelmail | =1.2.10 | |
Squirrelmail Squirrelmail | =0.4pre1 | |
Squirrelmail Squirrelmail | =1.2.5 | |
Squirrelmail Squirrelmail | =1.4.11 | |
Squirrelmail Squirrelmail | =1.0.3 | |
Squirrelmail Squirrelmail | =1.3.0 | |
Squirrelmail Squirrelmail | =1.0 | |
Squirrelmail Squirrelmail | =0.2 | |
Squirrelmail Squirrelmail | =1.2.8 | |
Squirrelmail Squirrelmail | =1.2.11 | |
Squirrelmail Squirrelmail | =0.5 | |
Squirrelmail Squirrelmail | <=1.4.17 | |
Squirrelmail Squirrelmail | =1.0pre3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.