CVE-2004-0519

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.
References
Link Resource
ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc Patch
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000858
http://marc.info/?l=bugtraq&m=108334862800260
http://rhn.redhat.com/errata/RHSA-2004-240.html Patch Vendor Advisory
http://secunia.com/advisories/11531 Patch Vendor Advisory
http://secunia.com/advisories/11686 Patch Vendor Advisory
http://secunia.com/advisories/11870 Patch Vendor Advisory
http://secunia.com/advisories/12289 Patch
http://security.gentoo.org/glsa/glsa-200405-16.xml Vendor Advisory
http://www.debian.org/security/2004/dsa-535 Patch Vendor Advisory
http://www.novell.com/linux/security/advisories/2005_19_sr.html Vendor Advisory
http://www.securityfocus.com/advisories/6827 Patch Vendor Advisory
http://www.securityfocus.com/archive/1/361857
http://www.securityfocus.com/bid/10246 Exploit Patch
https://bugzilla.fedora.us/show_bug.cgi?id=1733 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/16025
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1006
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10274
ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc Patch
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000858
http://marc.info/?l=bugtraq&m=108334862800260
http://rhn.redhat.com/errata/RHSA-2004-240.html Patch Vendor Advisory
http://secunia.com/advisories/11531 Patch Vendor Advisory
http://secunia.com/advisories/11686 Patch Vendor Advisory
http://secunia.com/advisories/11870 Patch Vendor Advisory
http://secunia.com/advisories/12289 Patch
http://security.gentoo.org/glsa/glsa-200405-16.xml Vendor Advisory
http://www.debian.org/security/2004/dsa-535 Patch Vendor Advisory
http://www.novell.com/linux/security/advisories/2005_19_sr.html Vendor Advisory
http://www.securityfocus.com/advisories/6827 Patch Vendor Advisory
http://www.securityfocus.com/archive/1/361857
http://www.securityfocus.com/bid/10246 Exploit Patch
https://bugzilla.fedora.us/show_bug.cgi?id=1733 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/16025
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1006
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10274
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sgi:propack:3.0:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.2.7:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.2.8:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.2.9:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.2.10:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.2.11:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.4:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:squirrelmail:squirrelmail:1.4.2:*:*:*:*:*:*:*

History

20 Nov 2024, 23:48

Type Values Removed Values Added
References () ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc - Patch () ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc - Patch
References () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000858 - () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000858 -
References () http://marc.info/?l=bugtraq&m=108334862800260 - () http://marc.info/?l=bugtraq&m=108334862800260 -
References () http://rhn.redhat.com/errata/RHSA-2004-240.html - Patch, Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2004-240.html - Patch, Vendor Advisory
References () http://secunia.com/advisories/11531 - Patch, Vendor Advisory () http://secunia.com/advisories/11531 - Patch, Vendor Advisory
References () http://secunia.com/advisories/11686 - Patch, Vendor Advisory () http://secunia.com/advisories/11686 - Patch, Vendor Advisory
References () http://secunia.com/advisories/11870 - Patch, Vendor Advisory () http://secunia.com/advisories/11870 - Patch, Vendor Advisory
References () http://secunia.com/advisories/12289 - Patch () http://secunia.com/advisories/12289 - Patch
References () http://security.gentoo.org/glsa/glsa-200405-16.xml - Vendor Advisory () http://security.gentoo.org/glsa/glsa-200405-16.xml - Vendor Advisory
References () http://www.debian.org/security/2004/dsa-535 - Patch, Vendor Advisory () http://www.debian.org/security/2004/dsa-535 - Patch, Vendor Advisory
References () http://www.novell.com/linux/security/advisories/2005_19_sr.html - Vendor Advisory () http://www.novell.com/linux/security/advisories/2005_19_sr.html - Vendor Advisory
References () http://www.securityfocus.com/advisories/6827 - Patch, Vendor Advisory () http://www.securityfocus.com/advisories/6827 - Patch, Vendor Advisory
References () http://www.securityfocus.com/archive/1/361857 - () http://www.securityfocus.com/archive/1/361857 -
References () http://www.securityfocus.com/bid/10246 - Exploit, Patch () http://www.securityfocus.com/bid/10246 - Exploit, Patch
References () https://bugzilla.fedora.us/show_bug.cgi?id=1733 - Patch () https://bugzilla.fedora.us/show_bug.cgi?id=1733 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/16025 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/16025 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1006 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1006 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10274 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10274 -

Information

Published : 2004-08-18 04:00

Updated : 2024-11-20 23:48


NVD link : CVE-2004-0519

Mitre link : CVE-2004-0519

CVE.ORG link : CVE-2004-0519


JSON object : View

Products Affected

sgi

  • propack

squirrelmail

  • squirrelmail