CVE
- Id
- 9067
- CVE No.
- CVE-2004-0639
- Status
- Candidate
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (1) the $mailer variable in read_body.php, (2) the $senderNames_part variable in mailbox_display.php, and possibly other vectors including (3) the $event_title variable or (4) the $event_text variable.
- Phase
- Assigned (20040708)
- Votes
- None (candidate not yet proposed)
- Comments