CVE-2004-0519
Summary
| CVE | CVE-2004-0519 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-08-18 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php. |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sgi | Propack | 3.0 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.0.4 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.0.5 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.2.0 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.2.1 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.2.10 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.2.11 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.2.2 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.2.3 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.2.4 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.2.5 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.2.6 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.2.7 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.2.8 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.2.9 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.4 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.4.1 | All | All | All |
| Application | Squirrelmail | Squirrelmail | 1.4.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-535-1 squirrelmail | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Patch, Vendor Advisory |
| bugzilla.fedora.us/show_bug.cgi | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.fedora.us | Patch |
| Secunia - Advisories - Conectiva update for squirrelmail | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch |
| Malformed Request | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Home - Conectiva | af854a3a-2127-422b-91ae-364da2661108 | distro.conectiva.com.br | |
| Secunia - Advisories - SquirrelMail Folder Name Cross-Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | Vendor Advisory |
| patches.sgi.com/support/free/security/advisories/20040604-01-U.asc | af854a3a-2127-422b-91ae-364da2661108 | patches.sgi.com | Patch |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Gentoo Linux Documentation -- Multiple XSS Vulnerabilities in SquirrelMail | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Vendor Advisory |
| 'SquirrelMail Cross Scripting Attacks....' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Patch, Vendor Advisory |
| Secunia - Advisories - Red Hat update for squirrelmail | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| SquirrelMail Folder Name Cross-Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch |
| Secunia - Advisories - Gentoo update for squirrelmail | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.