Vulnerability Name: | CVE-2002-1341 (CCN-10754) | ||||||||
Assigned: | 2002-12-02 | ||||||||
Published: | 2002-12-02 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in read_body.php for SquirrelMail 1.2.10, 1.2.9, and earlier allows remote attackers to insert script and HTML via the (1) mailbox and (2) passed_id parameters. | ||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Dec 02 2002 - 22:28:14 CST SquirrelMail v1.2.9 XSS bugs Source: MITRE Type: CNA CVE-2002-1341 Source: MISC Type: UNKNOWN http://f0kp.iplus.ru/bz/008.txt Source: BUGTRAQ Type: UNKNOWN 20021203 SquirrelMail v1.2.9 XSS bugs Source: BUGTRAQ Type: UNKNOWN 20021203 Re: SquirrelMail v1.2.9 XSS bugs Source: BUGTRAQ Type: UNKNOWN 20021215 GLSA: squirrelmail Source: CCN Type: RHSA-2003-042 Updated squirrelmail packages close cross-site scripting vulnerabilities Source: SECUNIA Type: UNKNOWN 8220 Source: DEBIAN Type: UNKNOWN DSA-220 Source: DEBIAN Type: DSA-220 squirrelmail -- cross site scripting Source: CCN Type: Gentoo Linux Security Announcement 200212-4 cross site scripting Source: CCN Type: OSVDB ID: 4266 SquirrelMail read_body.php XSS Source: REDHAT Type: Patch, Vendor Advisory RHSA-2003:042 Source: BID Type: Patch, Vendor Advisory 6302 Source: CCN Type: BID-6302 SquirrelMail read_body.php Cross Site Scripting Vulnerability Source: XF Type: UNKNOWN squirrelmail-readbody-xss(10754) Source: XF Type: UNKNOWN squirrelmail-readbody-xss(10754) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |