CVE
- Id
- 13301
- CVE No.
- CVE-2005-2095
- Status
- Candidate
- Description
- options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to modify or read the preferences of other users, conduct cross-site scripting XSS) attacks, and write arbitrary files.
- Phase
- Assigned (20050630)
- Votes
- None (candidate not yet proposed)
- Comments