Show filters
23 Total Results
Displaying 21-23 of 23
Sort by:
Attacker Value
Unknown
CVE-2004-0639
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (1) the $mailer variable in read_body.php, (2) the $senderNames_part variable in mailbox_display.php, and possibly other vectors including (3) the $event_title variable or (4) the $event_text variable.
0
Attacker Value
Unknown
CVE-2002-2086
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in magicHTML of SquirrelMail before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via (1) "<<script" in unspecified input fields or (2) a javascript: URL in the src attribute of an IMG tag.
0
Attacker Value
Unknown
CVE-2002-0516
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie.
0