CVE Vulnerabilities

CVE-2004-0519

Published: Aug 18, 2004 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.

Affected Software

Name Vendor Start Version End Version
Propack Sgi 3.0 3.0
Squirrelmail Squirrelmail 1.0.4 1.0.4
Squirrelmail Squirrelmail 1.0.5 1.0.5
Squirrelmail Squirrelmail 1.2.0 1.2.0
Squirrelmail Squirrelmail 1.2.1 1.2.1
Squirrelmail Squirrelmail 1.2.2 1.2.2
Squirrelmail Squirrelmail 1.2.3 1.2.3
Squirrelmail Squirrelmail 1.2.4 1.2.4
Squirrelmail Squirrelmail 1.2.5 1.2.5
Squirrelmail Squirrelmail 1.2.6 1.2.6
Squirrelmail Squirrelmail 1.2.7 1.2.7
Squirrelmail Squirrelmail 1.2.8 1.2.8
Squirrelmail Squirrelmail 1.2.9 1.2.9
Squirrelmail Squirrelmail 1.2.10 1.2.10
Squirrelmail Squirrelmail 1.2.11 1.2.11
Squirrelmail Squirrelmail 1.4 1.4
Squirrelmail Squirrelmail 1.4.1 1.4.1
Squirrelmail Squirrelmail 1.4.2 1.4.2
Red Hat Enterprise Linux 3 RedHat squirrelmail-0:1.4.3-0.e3.1 *

References