Oval Definition:oval:org.mitre.oval:tst:38669
Comment:squirrelmail is earlier than 0:1.4.8-5.el4_8.5
Type:rpminfo_testNamespace:linux
Check_Existence:at_least_one_existsCheck:at least one
State Operator:AND
References
Object:oval:org.mitre.oval:obj:14331
State:oval:org.mitre.oval:ste:11285
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:10441
V
functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message.
2013-04-29
oval:org.mitre.oval:def:10986
V
The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.
2013-04-29
oval:org.mitre.oval:def:11624
V
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).
2013-04-29
BACK