Show filters
154 Total Results
Displaying 131-140 of 154
Sort by:
Attacker Value
Unknown

CVE-2004-1498

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.
0
Attacker Value
Unknown

CVE-2004-1499

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.
0
Attacker Value
Unknown

CVE-2004-0521

Disclosure Date: August 18, 2004 (last updated February 22, 2025)
SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php.
0
Attacker Value
Unknown

CVE-2004-0520

Disclosure Date: August 18, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.
0
Attacker Value
Unknown

CVE-2004-0519

Disclosure Date: August 18, 2004 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.
0
Attacker Value
Unknown

CVE-2004-0639

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (1) the $mailer variable in read_body.php, (2) the $senderNames_part variable in mailbox_display.php, and possibly other vectors including (3) the $event_title variable or (4) the $event_text variable.
0
Attacker Value
Unknown

CVE-2003-0966

Disclosure Date: February 17, 2004 (last updated February 22, 2025)
Buffer overflow in the frm command in elm 2.5.6 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code via a long Subject line.
0
Attacker Value
Unknown

CVE-2003-1324

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Race condition in the can_open function in Elm ME+ 2.4, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group.
0
Attacker Value
Unknown

CVE-2003-1323

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Elm ME+ 2.4 before PL109S, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group via unspecified vectors.
0
Attacker Value
Unknown

CVE-2003-0160

Disclosure Date: April 02, 2003 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser.
0