Vulnerability Name: | CVE-2007-2631 (CCN-34219) | ||||||||
Assigned: | 2007-05-09 | ||||||||
Published: | 2007-05-09 | ||||||||
Updated: | 2018-10-16 | ||||||||
Summary: | Cross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actions as arbitrary users via unspecified vectors. Note: this issue might overlap CVE-2007-2589 or CVE-2002-1648. | ||||||||
CVSS v3 Severity: | 4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 6.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu May 10 2007 - 07:02:20 CDT squirrelmail CSRF vulnerability Source: MITRE Type: CNA CVE-2007-2589 Source: MITRE Type: CNA CVE-2007-2631 Source: CCN Type: Apple Security Update 2007-007 About Security Update 2007-007 Source: CCN Type: Apple Web site Apple security updates Source: OSVDB Type: UNKNOWN 35890 Source: CCN Type: RHSA-2007-0358 Moderate: squirrelmail security update Source: CCN Type: SA25200 SquirrelMail Cross-Site Scripting and Request Forgery Vulnerabilities Source: CCN Type: SA26235 Mac OS X Security Update Fixes Multiple Vulnerabilities Source: CCN Type: SECTRACK ID: 1018033 SquirrelMail Input Validation Holes in HTML Filter Permit Cross-Site Scripting Attacks Source: CCN Type: SourceForge.net SquirrelMail Source: CCN Type: ASA-2007-262 squirrelmail security update (RHSA-2007-0358) Source: CCN Type: OSVDB ID: 35889 SquirrelMail compose.php IMG Element SRC Attribute CSRF Source: CCN Type: OSVDB ID: 35890 SquirrelMail Unspecified CSRF Source: BUGTRAQ Type: UNKNOWN 20070510 squirrelmail CSRF vulnerability Source: BUGTRAQ Type: UNKNOWN 20070510 Re: squirrelmail CSRF vulnerability Source: CCN Type: BID-23910 SquirrelMail Multiple Cross Site Scripting Vulnerabilities Source: CCN Type: BID-25159 Apple Mac OS X 2007-007 Multiple Security Vulnerabilities Source: CCN Type: SquirrelMail Security Advisory 2007-05-09 Cross site scripting in HTML filter Source: XF Type: UNKNOWN squirrelmail-compose-csrf(34219) Source: SUSE Type: SUSE-SR:2007:013 SUSE Security Summary Report | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |