It was reported that SquirrelMail did not implement protections against cross-site request forgery (CSRF) attacks. This can be exploited to e.g. change user preferences, delete emails, and potentially send emails when a logged-in user visits a malicious web page.
Upstream advisory: http://www.squirrelmail.org/security/issue/2009-08-12
Upstream patch: http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&revision=13818
Issue was first addressed in 1.4.20RC1.
Secunia advisory: http://secunia.com/advisories/34627/
Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to hijack the authentication of unspecified victims via vectors involving (1) the empty trash implementation and (2) the Index Order (aka optionsorder) page, a different issue than CVE-2010-4555.
The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number.
CRLF injection vulnerability in SquirrelMail 1.4.21 and earlier allows remote attackers to modify or add preference values via a \n (newline) character, a different vulnerability than CVE-2010-4555.
Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
Reference: BUGTRAQ:20080922 Squirrelmail: Session hijacking vulnerability, CVE-2008-3663 Reference: URL:http://www.securityfocus.com/archive/1/archive/1/496601/100/0/threaded Reference: MISC:http://int21.de/cve/CVE-2008-3663-squirrelmail.html Reference: BID:31321 Reference: URL:http://www.securityfocus.com/bid/31321
An cross-site scripting (XSS) flaw was found in the way SquirrelMail performed sanitization of MIME messages containing certain <style> HTML tags. A remote attacker could provide a specially-crafted message, which once opened in SquirrelMail webmail client could lead to arbitrary JavaScript or HTML code execution.
Upstream advisory: [1] http://www.squirrelmail.org/security/issue/2011-07-10
Relevant patch: [2] http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=revision&revision=14121
Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an e-mail message.