Vulnerabilities > CVE-2002-1341 - Cross-Site Scripting vulnerability in SquirrelMail read_body.php

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
squirrelmail
nessus

Summary

Cross-site scripting (XSS) vulnerability in read_body.php for SquirrelMail 1.2.10, 1.2.9, and earlier allows remote attackers to insert script and HTML via the (1) mailbox and (2) passed_id parameters.

Nessus

  • NASL familyCGI abuses : XSS
    NASL idSQUIRREMAIL_CROSS_SITE_SCRIPTING.NASL
    descriptionThe remote host seems to be vulnerable to a security problem in SquirrelMail. The
    last seen2020-06-01
    modified2020-06-02
    plugin id11415
    published2003-03-19
    reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/11415
    titleSquirrelMail 1.2.9 / 1.2.10 read_body.php Multiple Parameter XSS
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-220.NASL
    descriptionA cross site scripting vulnerability has been discovered in squirrelmail, a feature-rich webmail package written in PHP4. Squirrelmail doesn
    last seen2020-06-01
    modified2020-06-02
    plugin id15057
    published2004-09-29
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/15057
    titleDebian DSA-220-1 : squirrelmail - XSS

Redhat

advisories
rhsa
idRHSA-2003:042