CVE
- Id
- 8947
- CVE No.
- CVE-2004-0519
- Status
- Candidate
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.
- Phase
- Assigned (20040602)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
57385 | 8947 | CVE-2004-0519 | BUGTRAQ:20040429 SquirrelMail Cross Scripting Attacks.... | View |
57386 | 8947 | CVE-2004-0519 | URL:http://marc.info/?l=bugtraq&m=108334862800260 | View |
57387 | 8947 | CVE-2004-0519 | BUGTRAQ:20040430 Re: SquirrelMail Cross Scripting Attacks.... | View |
57388 | 8947 | CVE-2004-0519 | URL:http://www.securityfocus.com/archive/1/361857 | View |
57389 | 8947 | CVE-2004-0519 | CONECTIVA:CLA-2004:858 | View |
57390 | 8947 | CVE-2004-0519 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000858 | View |
57391 | 8947 | CVE-2004-0519 | DEBIAN:DSA-535 | View |
57392 | 8947 | CVE-2004-0519 | URL:http://www.debian.org/security/2004/dsa-535 | View |
57393 | 8947 | CVE-2004-0519 | FEDORA:FEDORA-2004-160 | View |
57394 | 8947 | CVE-2004-0519 | URL:http://www.securityfocus.com/advisories/6827 | View |
57395 | 8947 | CVE-2004-0519 | FEDORA:FEDORA-2004-1733 | View |
57396 | 8947 | CVE-2004-0519 | URL:https://bugzilla.fedora.us/show_bug.cgi?id=1733 | View |
57397 | 8947 | CVE-2004-0519 | GENTOO:GLSA-200405-16 | View |
57398 | 8947 | CVE-2004-0519 | URL:http://security.gentoo.org/glsa/glsa-200405-16.xml | View |
57399 | 8947 | CVE-2004-0519 | REDHAT:RHSA-2004:240 | View |
57400 | 8947 | CVE-2004-0519 | URL:http://rhn.redhat.com/errata/RHSA-2004-240.html | View |
57401 | 8947 | CVE-2004-0519 | SGI:20040604-01-U | View |
57402 | 8947 | CVE-2004-0519 | URL:ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc | View |
57403 | 8947 | CVE-2004-0519 | SUSE:SUSE-SR:2005:019 | View |
57404 | 8947 | CVE-2004-0519 | URL:http://www.novell.com/linux/security/advisories/2005_19_sr.html | View |
57405 | 8947 | CVE-2004-0519 | BID:10246 | View |
57406 | 8947 | CVE-2004-0519 | URL:http://www.securityfocus.com/bid/10246 | View |
57407 | 8947 | CVE-2004-0519 | OVAL:oval:org.mitre.oval:def:1006 | View |
57408 | 8947 | CVE-2004-0519 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1006 | View |
57409 | 8947 | CVE-2004-0519 | OVAL:oval:org.mitre.oval:def:10274 | View |
57410 | 8947 | CVE-2004-0519 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10274 | View |
57411 | 8947 | CVE-2004-0519 | SECUNIA:11531 | View |
57412 | 8947 | CVE-2004-0519 | URL:http://secunia.com/advisories/11531 | View |
57413 | 8947 | CVE-2004-0519 | SECUNIA:11686 | View |
57414 | 8947 | CVE-2004-0519 | URL:http://secunia.com/advisories/11686 | View |
57415 | 8947 | CVE-2004-0519 | SECUNIA:11870 | View |
57416 | 8947 | CVE-2004-0519 | URL:http://secunia.com/advisories/11870 | View |
57417 | 8947 | CVE-2004-0519 | SECUNIA:12289 | View |
57418 | 8947 | CVE-2004-0519 | URL:http://secunia.com/advisories/12289 | View |
57419 | 8947 | CVE-2004-0519 | XF:squirrel-composephp-xss(16025) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
62870 | JVNDB-2004-000212 | SquirrelMail に不適切な添付ファイルのパラメータの妥当性確認におけるクロスサイトスクリプティングの脆弱性 | SquirrelMail には、電子メールの添付ファイルに関する情報を取り扱うためのパラメータが適切にサニタイズされていない不備のため、クロスサイトスクリプティング攻撃が可能である脆弱性が存在します。 | CVE-2004-0520 | 8947 | 6.8 | http://jvndb.jvn.jp/ja/contents/2004/JVNDB-2004-000212.html | View |