CVE Vulnerabilities

CVE-2005-2095

Published: Jul 13, 2005 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to modify or read the preferences of other users, conduct cross-site scripting XSS) attacks, and write arbitrary files.

Affected Software 

Name Vendor Start Version End Version
Squirrelmail Squirrelmail 1.0.4 (including) 1.0.4 (including)
Squirrelmail Squirrelmail 1.0.5 (including) 1.0.5 (including)
Squirrelmail Squirrelmail 1.2.0 (including) 1.2.0 (including)
Squirrelmail Squirrelmail 1.2.1 (including) 1.2.1 (including)
Squirrelmail Squirrelmail 1.2.2 (including) 1.2.2 (including)
Squirrelmail Squirrelmail 1.2.3 (including) 1.2.3 (including)
Squirrelmail Squirrelmail 1.2.4 (including) 1.2.4 (including)
Squirrelmail Squirrelmail 1.2.5 (including) 1.2.5 (including)
Squirrelmail Squirrelmail 1.2.6 (including) 1.2.6 (including)
Squirrelmail Squirrelmail 1.2.7 (including) 1.2.7 (including)
Squirrelmail Squirrelmail 1.2.8 (including) 1.2.8 (including)
Squirrelmail Squirrelmail 1.2.9 (including) 1.2.9 (including)
Squirrelmail Squirrelmail 1.2.10 (including) 1.2.10 (including)
Squirrelmail Squirrelmail 1.2.11 (including) 1.2.11 (including)
Squirrelmail Squirrelmail 1.4 (including) 1.4 (including)
Squirrelmail Squirrelmail 1.4.0 (including) 1.4.0 (including)
Squirrelmail Squirrelmail 1.4.1 (including) 1.4.1 (including)
Squirrelmail Squirrelmail 1.4.2 (including) 1.4.2 (including)
Squirrelmail Squirrelmail 1.4.3 (including) 1.4.3 (including)
Squirrelmail Squirrelmail 1.4.3_rc1 (including) 1.4.3_rc1 (including)
Squirrelmail Squirrelmail 1.4.3a (including) 1.4.3a (including)
Squirrelmail Squirrelmail 1.44 (including) 1.44 (including)
Red Hat Enterprise Linux 3 RedHat squirrelmail-0:1.4.3a-11.EL3 *
Red Hat Enterprise Linux 4 RedHat squirrelmail-0:1.4.3a-12.EL4 *
Squirrelmail Ubuntu dapper *
Squirrelmail Ubuntu devel *
Squirrelmail Ubuntu edgy *
Squirrelmail Ubuntu feisty *

References