CVE
- Id
- 8948
- CVE No.
- CVE-2004-0520
- Status
- Candidate
- Description
- Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.
- Phase
- Assigned (20040602)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
57420 | 8948 | CVE-2004-0520 | BUGTRAQ:20040530 RS-2004-1: SquirrelMail "Content-Type" XSS vulnerability | View |
57421 | 8948 | CVE-2004-0520 | URL:http://marc.info/?l=bugtraq&m=108611554415078&w=2 | View |
57422 | 8948 | CVE-2004-0520 | MISC:http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-1.txt | View |
57423 | 8948 | CVE-2004-0520 | MLIST:[squirrelmail-cvs] 20040523 [SM-CVS] CVS: squirrelmail/functions mime.php,1.265.2.27,1.265.2.28 | View |
57424 | 8948 | CVE-2004-0520 | URL:http://marc.info/?l=squirrelmail-cvs&m=108532891231712 | View |
57425 | 8948 | CVE-2004-0520 | CONECTIVA:CLA-2004:858 | View |
57426 | 8948 | CVE-2004-0520 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000858 | View |
57427 | 8948 | CVE-2004-0520 | DEBIAN:DSA-535 | View |
57428 | 8948 | CVE-2004-0520 | URL:http://www.debian.org/security/2004/dsa-535 | View |
57429 | 8948 | CVE-2004-0520 | FEDORA:FEDORA-2004-1733 | View |
57430 | 8948 | CVE-2004-0520 | URL:https://bugzilla.fedora.us/show_bug.cgi?id=1733 | View |
57431 | 8948 | CVE-2004-0520 | FEDORA:FEDORA-2004-160 | View |
57432 | 8948 | CVE-2004-0520 | URL:http://www.securityfocus.com/advisories/6827 | View |
57433 | 8948 | CVE-2004-0520 | GENTOO:GLSA-200406-08 | View |
57434 | 8948 | CVE-2004-0520 | URL:http://www.gentoo.org/security/en/glsa/glsa-200406-08.xml | View |
57435 | 8948 | CVE-2004-0520 | REDHAT:RHSA-2004:240 | View |
57436 | 8948 | CVE-2004-0520 | URL:http://rhn.redhat.com/errata/RHSA-2004-240.html | View |
57437 | 8948 | CVE-2004-0520 | SGI:20040604-01-U | View |
57438 | 8948 | CVE-2004-0520 | URL:ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc | View |
57439 | 8948 | CVE-2004-0520 | BID:10439 | View |
57440 | 8948 | CVE-2004-0520 | URL:http://www.securityfocus.com/bid/10439 | View |
57441 | 8948 | CVE-2004-0520 | OVAL:oval:org.mitre.oval:def:1012 | View |
57442 | 8948 | CVE-2004-0520 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1012 | View |
57443 | 8948 | CVE-2004-0520 | OVAL:oval:org.mitre.oval:def:10766 | View |
57444 | 8948 | CVE-2004-0520 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10766 | View |
57445 | 8948 | CVE-2004-0520 | SECUNIA:11870 | View |
57446 | 8948 | CVE-2004-0520 | URL:http://secunia.com/advisories/11870 | View |
57447 | 8948 | CVE-2004-0520 | SECUNIA:12289 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
62823 | JVNDB-2004-000165 | SquirrelMail における SQL インジェクションを受ける脆弱性 | ------------ | CVE-2004-0521 | 8948 | 10 | http://jvndb.jvn.jp/ja/contents/2004/JVNDB-2004-000165.html | View |