Cross-site scripting (XSS) vulnerability in add.php in Address Add Plugin 1.9 and 2.0 for Squirrelmail allows remote attackers to inject arbitrary web script or HTML via the IMG tag.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Address_add_plugin | Squirrelmail | 1.9 (including) | 1.9 (including) |
| Address_add_plugin | Squirrelmail | 2.0 (including) | 2.0 (including) |