Oval Definition:oval:org.mitre.oval:tst:29772
Comment:squirrelmail is earlier than 0:1.4.3-0.e3.1
Type:rpminfo_testNamespace:linux
Check_Existence:at_least_one_existsCheck:at least one
State Operator:AND
References
Object:oval:org.mitre.oval:obj:14331
State:oval:org.mitre.oval:ste:9664
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:10274
V
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.
2013-04-29
oval:org.mitre.oval:def:10766
V
Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.
2013-04-29
oval:org.mitre.oval:def:11446
V
SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php.
2013-04-29
BACK