Vulnerability Name:

CVE-2004-0639 (CCN-16285)

Assigned:2004-05-30
Published:2004-05-30
Updated:2017-07-11
Summary:Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (1) the $mailer variable in read_body.php, (2) the $senderNames_part variable in mailbox_display.php, and possibly other vectors including (3) the $event_title variable or (4) the $event_text variable.
CVSS v3 Severity:5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: CCN
Type: BugTraq Mailing List, Thu Jun 03 2004 - 07:43:27 CDT
[openwebmail] Fw: Re: XSS bug.

Source: CONFIRM
Type: UNKNOWN
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=257973

Source: MITRE
Type: CNA
CVE-2004-0520

Source: MITRE
Type: CNA
CVE-2004-0639

Source: CONECTIVA
Type: UNKNOWN
CLA-2004:858

Source: CCN
Type: Conectiva Linux Announcement CLSA-2004:858
Several vulnerabilities in SquirrelMail

Source: CCN
Type: IlohaMail Web site
IlohaMail

Source: BUGTRAQ
Type: UNKNOWN
20040530 RS-2004-1: SquirrelMail "Content-Type" XSS vulnerability

Source: CCN
Type: Open WebMail Web site
Index of /openwebmail/download

Source: CCN
Type: RHSA-2004-240
squirrelmail security update

Source: DEBIAN
Type: Patch, Vendor Advisory
DSA-535

Source: DEBIAN
Type: DSA-535
squirrelmail -- several vulnerabilities

Source: CCN
Type: GLSA-200406-08
Squirrelmail: Another XSS vulnerability

Source: CCN
Type: OSVDB ID: 51270
IlohaMail Email Header XSS

Source: CCN
Type: OSVDB ID: 54626
Open WebMail (OWM) E-mail Multiple Content Header XSS

Source: CCN
Type: OSVDB ID: 8291
SquirrelMail read_body.php Multiple Parameter XSS

Source: CCN
Type: OSVDB ID: 8292
SquirrelMail mailbox_display.php Multiple Parameter XSS

Source: CCN
Type: RS-Labs Security Advisory RS-2004-1
SquirrelMail "Content-Type" XSS vulnerability

Source: MISC
Type: Vendor Advisory
http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-1.txt

Source: CCN
Type: BID-10439
SquirrelMail Email Header HTML Injection Vulnerability

Source: BID
Type: Exploit, Patch
10450

Source: CCN
Type: BID-10450
SquirrelMail From Email Header HTML Injection Vulnerability

Source: CCN
Type: BID-10667
Open WebMail Email Header HTML Injection Vulnerability

Source: CCN
Type: BID-10668
IlohaMail Email Header HTML Injection Vulnerability

Source: CCN
Type: SquirrelMail Web site
SquirrelMail - Webmail for Nuts!

Source: XF
Type: UNKNOWN
squirrelmail-from-header-xss(16285)

Source: XF
Type: UNKNOWN
squirrelmail-from-header-xss(16285)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:open_webmail:open_webmail:2.30:*:*:*:*:*:*:*
  • OR cpe:/a:open_webmail:open_webmail:2.31:*:*:*:*:*:*:*
  • OR cpe:/a:open_webmail:open_webmail:2.32:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:propack:3.0:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.2.4:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.2.5:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.2.6:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.2.7:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.2.8:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.2.9:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.2.10:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.2.11:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.4:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.4.3_rc1:*:*:*:*:*:*:*
  • OR cpe:/a:squirrelmail:squirrelmail:1.5_dev:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.debian:def:535
    V
    several vulnerabilities
    2004-08-02
    BACK
    open_webmail open webmail 2.30
    open_webmail open webmail 2.31
    open_webmail open webmail 2.32
    sgi propack 3.0
    squirrelmail squirrelmail 1.2.0
    squirrelmail squirrelmail 1.2.1
    squirrelmail squirrelmail 1.2.2
    squirrelmail squirrelmail 1.2.3
    squirrelmail squirrelmail 1.2.4
    squirrelmail squirrelmail 1.2.5
    squirrelmail squirrelmail 1.2.6
    squirrelmail squirrelmail 1.2.7
    squirrelmail squirrelmail 1.2.8
    squirrelmail squirrelmail 1.2.9
    squirrelmail squirrelmail 1.2.10
    squirrelmail squirrelmail 1.2.11
    squirrelmail squirrelmail 1.4
    squirrelmail squirrelmail 1.4.1
    squirrelmail squirrelmail 1.4.2
    squirrelmail squirrelmail 1.4.3_rc1
    squirrelmail squirrelmail 1.5_dev