CVE
- Id
- 5660
- CVE No.
- CVE-2002-1276
- Status
- Candidate
- Description
- An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving it open to cross-site scripting attacks.
- Phase
- Modified (20071113)
- Votes
- ACCEPT(4) Armstrong, Cole, Cox, Green
- Comments