Vulnerability Name: CVE-2004-0519 (CCN-16025) Assigned: 2004-04-29 Published: 2004-04-29 Updated: 2017-10-11 Summary: Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php. CVSS v3 Severity: 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): HighPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): HighAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-Other Vulnerability Consequences: Gain Access References: Source: SGI Type: Patch20040604-01-U Source: CCN Type: BugTraq Mailing List, Thu Apr 29 2004 - 16:09:06 CDT SquirrelMail Cross Scripting Attacks.... Source: CCN Type: BugTraq Mailing List, Fri Apr 30 2004 - 15:22:47 CDTRe: SquirrelMail Cross Scripting Attacks.... Source: MITRE Type: CNACVE-2004-0519 Source: CONECTIVA Type: UNKNOWNCLA-2004:858 Source: CCN Type: Conectiva Linux Announcement CLSA-2004:858Several vulnerabilities in SquirrelMail Source: BUGTRAQ Type: UNKNOWN20040429 SquirrelMail Cross Scripting Attacks.... Source: CCN Type: RHSA-2004-240squirrelmail security update Source: REDHAT Type: Patch, Vendor AdvisoryRHSA-2004:240 Source: CCN Type: SA11531SquirrelMail Folder Name Cross-Site Scripting Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory11531 Source: SECUNIA Type: Patch, Vendor Advisory11686 Source: SECUNIA Type: Patch, Vendor Advisory11870 Source: SECUNIA Type: Patch12289 Source: GENTOO Type: Vendor AdvisoryGLSA-200405-16 Source: DEBIAN Type: Patch, Vendor AdvisoryDSA-535 Source: DEBIAN Type: DSA-535squirrelmail -- several vulnerabilities Source: CCN Type: GLSA-200405-16Multiple XSS Vulnerabilities in SquirrelMail Source: SUSE Type: Vendor AdvisorySUSE-SR:2005:019 Source: FEDORA Type: Patch, Vendor AdvisoryFEDORA-2004-160 Source: BUGTRAQ Type: UNKNOWN20040430 Re: SquirrelMail Cross Scripting Attacks.... Source: BID Type: Exploit, Patch10246 Source: CCN Type: BID-10246SquirrelMail Folder Name Cross-Site Scripting Vulnerability Source: CCN Type: SquirrelMail Web siteSquirrelMail - Webmail for Nuts! Source: FEDORA Type: PatchFEDORA-2004-1733 Source: XF Type: UNKNOWNsquirrel-composephp-xss(16025) Source: XF Type: UNKNOWNsquirrel-composephp-xss(16025) Source: OVAL Type: UNKNOWNoval:org.mitre.oval:def:1006 Source: OVAL Type: UNKNOWNoval:org.mitre.oval:def:10274 Source: SUSE Type: SUSE-SR:2005:019SUSE Security Summary Report Vulnerable Configuration: Configuration 1 :cpe:/a:sgi:propack:3.0:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.0.4:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.0.5:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.2.0:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.2.1:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.2.2:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.2.3:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.2.4:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.2.5:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.2.6:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.2.7:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.2.8:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.2.9:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.2.10:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.2.11:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.4:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.4.1:*:*:*:*:*:*:* OR cpe:/a:squirrelmail:squirrelmail:1.4.2:*:*:*:*:*:*:* Configuration RedHat 1 :cpe:/o:redhat:enterprise_linux:*:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:squirrelmail:squirrelmail:1.4.2:*:*:*:*:*:*:* AND cpe:/o:redhat:linux:3.0:*:*:*:*:*:*:* OR cpe:/o:debian:debian_linux:3.0:*:*:*:*:*:*:* OR cpe:/o:gentoo:linux:*:*:*:*:*:*:*:* OR cpe:/o:conectiva:linux:9.0:*:*:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:3::ws:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:3::es:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:3::as:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:3::desktop:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
sgi propack 3.0
squirrelmail squirrelmail 1.0.4
squirrelmail squirrelmail 1.0.5
squirrelmail squirrelmail 1.2.0
squirrelmail squirrelmail 1.2.1
squirrelmail squirrelmail 1.2.2
squirrelmail squirrelmail 1.2.3
squirrelmail squirrelmail 1.2.4
squirrelmail squirrelmail 1.2.5
squirrelmail squirrelmail 1.2.6
squirrelmail squirrelmail 1.2.7
squirrelmail squirrelmail 1.2.8
squirrelmail squirrelmail 1.2.9
squirrelmail squirrelmail 1.2.10
squirrelmail squirrelmail 1.2.11
squirrelmail squirrelmail 1.4
squirrelmail squirrelmail 1.4.1
squirrelmail squirrelmail 1.4.2
squirrelmail squirrelmail 1.4.2
redhat linux 3.0
debian debian linux 3.0
gentoo linux *
conectiva linux 9.0
redhat enterprise linux 3
redhat enterprise linux 3
redhat enterprise linux 3
redhat enterprise linux 3