{"api_version":"1","generated_at":"2026-07-23T04:32:32+00:00","cve":"CVE-2008-3663","urls":{"html":"https://cve.report/CVE-2008-3663","api":"https://cve.report/api/cve/CVE-2008-3663.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3663","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3663"},"summary":{"title":"CVE-2008-3663","description":"Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-09-24 14:56:52","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-310","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/31321","name":"http://www.securityfocus.com/bid/31321","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SquirrelMail Insecure Cookie Disclosure Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/496601/100/0/threaded","name":"http://www.securityfocus.com/archive/1/496601/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.nabble.com/ANNOUNCE:-SquirrelMail-1.4.16-Released-td19711998.html","name":"http://www.nabble.com/ANNOUNCE:-SquirrelMail-1.4.16-Released-td19711998.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Nabble - squirrelmail-devel - ANNOUNCE: SquirrelMail 1.4.16 Released","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://int21.de/cve/CVE-2008-3663-squirrelmail.html","name":"http://int21.de/cve/CVE-2008-3663-squirrelmail.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Squirrelmail: Session hijacking vulnerability, CVE-2008-3663","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45700","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45700","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html","name":"http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2009:004","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT3438","name":"http://support.apple.com/kb/HT3438","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of Security Update 2009-001","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/4304","name":"http://securityreason.com/securityalert/4304","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Squirrelmail: Session hijacking vulnerability - SecurityReason.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10548","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10548","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html","name":"http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"APPLE-SA-2009-02-12 Security Update 2009-001","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00003.html","name":"http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2008:028","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/33937","name":"http://secunia.com/advisories/33937","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3663","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3663","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3663","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"squirrelmail","cpe5":"squirrelmail","cpe6":"1.4.15","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2008-3663","organization":"Red Hat","lastmodified":"2009-01-12","contributor":"Tomas Hoger","statementText":"This issue has been fixed in the affected Red Hat Enterprise Linux versions via: https://rhn.redhat.com/errata/RHSA-2009-0010.html","cve_year":"2008","cve_id":"3663","crc32":"4d1d05ea"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:45:19.086Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.nabble.com/ANNOUNCE:-SquirrelMail-1.4.16-Released-td19711998.html"},{"name":"33937","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33937"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://int21.de/cve/CVE-2008-3663-squirrelmail.html"},{"name":"31321","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/31321"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT3438"},{"name":"4304","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4304"},{"name":"APPLE-SA-2009-02-12","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html"},{"name":"20080922 Squirrelmail: Session hijacking vulnerability, CVE-2008-3663","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/496601/100/0/threaded"},{"name":"squirrelmail-cookie-session-hijacking(45700)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45700"},{"name":"SUSE-SR:2009:004","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html"},{"name":"SUSE-SR:2008:028","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00003.html"},{"name":"oval:org.mitre.oval:def:10548","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10548"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-09-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.nabble.com/ANNOUNCE:-SquirrelMail-1.4.16-Released-td19711998.html"},{"name":"33937","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33937"},{"tags":["x_refsource_MISC"],"url":"http://int21.de/cve/CVE-2008-3663-squirrelmail.html"},{"name":"31321","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/31321"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT3438"},{"name":"4304","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4304"},{"name":"APPLE-SA-2009-02-12","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html"},{"name":"20080922 Squirrelmail: Session hijacking vulnerability, CVE-2008-3663","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/496601/100/0/threaded"},{"name":"squirrelmail-cookie-session-hijacking(45700)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45700"},{"name":"SUSE-SR:2009:004","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html"},{"name":"SUSE-SR:2008:028","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00003.html"},{"name":"oval:org.mitre.oval:def:10548","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10548"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3663","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.nabble.com/ANNOUNCE:-SquirrelMail-1.4.16-Released-td19711998.html","refsource":"CONFIRM","url":"http://www.nabble.com/ANNOUNCE:-SquirrelMail-1.4.16-Released-td19711998.html"},{"name":"33937","refsource":"SECUNIA","url":"http://secunia.com/advisories/33937"},{"name":"http://int21.de/cve/CVE-2008-3663-squirrelmail.html","refsource":"MISC","url":"http://int21.de/cve/CVE-2008-3663-squirrelmail.html"},{"name":"31321","refsource":"BID","url":"http://www.securityfocus.com/bid/31321"},{"name":"http://support.apple.com/kb/HT3438","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT3438"},{"name":"4304","refsource":"SREASON","url":"http://securityreason.com/securityalert/4304"},{"name":"APPLE-SA-2009-02-12","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html"},{"name":"20080922 Squirrelmail: Session hijacking vulnerability, CVE-2008-3663","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/496601/100/0/threaded"},{"name":"squirrelmail-cookie-session-hijacking(45700)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45700"},{"name":"SUSE-SR:2009:004","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html"},{"name":"SUSE-SR:2008:028","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00003.html"},{"name":"oval:org.mitre.oval:def:10548","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10548"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3663","datePublished":"2008-09-24T14:00:00.000Z","dateReserved":"2008-08-12T00:00:00.000Z","dateUpdated":"2024-08-07T09:45:19.086Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-09-24 14:56:52","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-310","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:squirrelmail:squirrelmail:1.4.15:*:*:*:*:*:*:*","matchCriteriaId":"0986D113-C9F9-4645-8968-D165EC6B917D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3663","Ordinal":"1","Title":"CVE-2008-3663","CVE":"CVE-2008-3663","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3663","Ordinal":"1","NoteData":"Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.","Type":"Description","Title":"CVE-2008-3663"},{"CveYear":"2008","CveId":"3663","Ordinal":"2","NoteData":"2008-09-24","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3663","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}