Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2010-2813

Disclosure Date: August 19, 2010 (last updated October 04, 2023)
functions/imap_general.php in SquirrelMail before 1.4.21 does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preferences files.
0
Attacker Value
Unknown

CVE-2009-1580

Disclosure Date: May 14, 2009 (last updated October 04, 2023)
Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie.
0
Attacker Value
Unknown

CVE-2006-4019

Disclosure Date: August 11, 2006 (last updated October 04, 2023)
Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variables and read or write the attachments and preferences of other users.
0
Attacker Value
Unknown

CVE-2005-2095

Disclosure Date: July 13, 2005 (last updated October 04, 2023)
options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to modify or read the preferences of other users, conduct cross-site scripting XSS) attacks, and write arbitrary files.
0
Attacker Value
Unknown

CVE-2005-1769

Disclosure Date: June 16, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in (1) the URL or (2) an e-mail message.
0
Attacker Value
Unknown

CVE-2005-0104

Disclosure Date: January 29, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via certain integer variables.
0