CVE Vulnerabilities

CVE-2005-1308

Published: Apr 15, 2005 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML.

Affected Software

Name Vendor Start Version End Version
Sqwebmail Inter7 3.4.1 (including) 3.4.1 (including)
Sqwebmail Inter7 3.5.0 (including) 3.5.0 (including)
Sqwebmail Inter7 3.5.1 (including) 3.5.1 (including)
Sqwebmail Inter7 3.5.2 (including) 3.5.2 (including)
Sqwebmail Inter7 3.5.3 (including) 3.5.3 (including)
Sqwebmail Inter7 3.6.0 (including) 3.6.0 (including)
Sqwebmail Inter7 3.6.1 (including) 3.6.1 (including)
Sqwebmail Inter7 4.0.4_2004-05-24 (including) 4.0.4_2004-05-24 (including)
Sqwebmail Inter7 4.0.5 (including) 4.0.5 (including)

References