Show filters
35 Total Results
Displaying 31-35 of 35
Sort by:
Attacker Value
Unknown
CVE-2005-0103
Disclosure Date: January 24, 2005 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code.
0
Attacker Value
Unknown
CVE-2004-0521
Disclosure Date: August 18, 2004 (last updated February 22, 2025)
SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php.
0
Attacker Value
Unknown
CVE-2004-0520
Disclosure Date: August 18, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.
0
Attacker Value
Unknown
CVE-2004-0519
Disclosure Date: August 18, 2004 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.
0
Attacker Value
Unknown
CVE-2004-0639
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (1) the $mailer variable in read_body.php, (2) the $senderNames_part variable in mailbox_display.php, and possibly other vectors including (3) the $event_title variable or (4) the $event_text variable.
0