Vulnerability Name: | CVE-2002-1131 (CCN-10145) | ||||||||
Assigned: | 2002-09-19 | ||||||||
Published: | 2002-09-19 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: BUGTRAQ Type: Exploit, Vendor Advisory 20020919 Squirrel Mail 1.2.7 XSS Exploit Source: CCN Type: BugTraq Mailing List, Thu Sep 19 2002 - 16:14:28 CDT Squirrel Mail 1.2.7 XSS Exploit Source: CCN Type: BugTraq Mailing List, Thu Sep 19 2002 - 16:51:09 CDT Re: Squirrel Mail 1.2.7 XSS Exploit Source: MITRE Type: CNA CVE-2002-1131 Source: CCN Type: RHSA-2002-204 Updated squirrelmail packages close cross-site scripting vulnerabilities Source: CONFIRM Type: UNKNOWN http://sourceforge.net/project/shownotes.php?group_id=311&release_id=110774 Source: DEBIAN Type: UNKNOWN DSA-191 Source: DEBIAN Type: DSA-191 squirrelmail -- cross site scripting Source: XF Type: Vendor Advisory squirrelmail-php-xss(10145) Source: CCN Type: OSVDB ID: 4262 SquirrelMail addressbook.php Multiple Parameter XSS Source: CCN Type: OSVDB ID: 4263 SquirrelMail options.php optpage Parameter XSS Source: CCN Type: OSVDB ID: 4264 SquirrelMail search.php Multiple Parameter XSS Source: CCN Type: OSVDB ID: 4265 SquirrelMail help.php chapter Parameter XSS Source: REDHAT Type: Patch, Vendor Advisory RHSA-2002:204 Source: BID Type: Exploit, Patch, Vendor Advisory 5763 Source: CCN Type: BID-5763 SquirrelMail Multiple Cross Site Scripting Vulnerablities Source: CCN Type: SquirrelMail Web site SquirrelMail - Webmail for Nuts! Source: XF Type: UNKNOWN squirrelmail-php-xss(10145) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |