Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Roman Medina

#16051de 53,640
16.8CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2004-1632
6.8
2004-06-03
Squirrelmail · Squirrelmail · CVE-2004-0520
**Name of the Vulnerable Software and Affected Versions** SquirrelMail versions prior to 1.4.3 **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to insert arbitrary HTML and script via the content-type mail header. This can be achieved by exploiting the mime.php file. **Recommendations** For versions prior to 1.4.3, update to version 1.4.3 or later to resolve the issue.
PT-2004-1633
10
2004-06-03
Squirrelmail · Squirrelmail · CVE-2004-0521
**Name of the Vulnerable Software and Affected Versions** SquirrelMail versions prior to 1.4.3 RC1 **Description** The issue allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via the "abook database.php" endpoint. **Recommendations** For versions prior to 1.4.3 RC1, update to version 1.4.3 RC1 or later to resolve the issue.