SquirrelMail Multiple Cross Site Scripting and Input Validation Vulnerabilities
BID:21414
Info
SquirrelMail Multiple Cross Site Scripting and Input Validation Vulnerabilities
| Bugtraq ID: | 21414 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-6142 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2006 12:00AM |
| Updated: | Mar 19 2015 08:46AM |
| Credit: | Martijn Brinkers is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server SDK 9 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 SuSE Linux 9.3 SquirrelMail SquirrelMail 1.4.8 SquirrelMail SquirrelMail 1.4.7 SquirrelMail SquirrelMail 1.4.6 -rc1 SquirrelMail SquirrelMail 1.4.6 -cvs SquirrelMail SquirrelMail 1.4.6 SquirrelMail SquirrelMail 1.4.5 SquirrelMail SquirrelMail 1.4.4 RC1 SquirrelMail SquirrelMail 1.4.4 SquirrelMail SquirrelMail 1.4.3 RC1 SquirrelMail SquirrelMail 1.4.3 r3 SquirrelMail SquirrelMail 1.4.3 a SquirrelMail SquirrelMail 1.4.3 SquirrelMail SquirrelMail 1.4.2 SquirrelMail SquirrelMail 1.4.1 SquirrelMail SquirrelMail 1.4 RC1 SquirrelMail SquirrelMail 1.4 SGI ProPack 3.0 SP6 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Office Server S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Openexchange Server S.u.S.E. Linux Office Server S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux Desktop 10 S.u.S.E. Linux Database Server 0 S.u.S.E. Linux Connectivity Server S.u.S.E. Linux 10.1 S.u.S.E. Linux 10.0 rPath rPath Linux 1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Desktop 4.0 RedHat Desktop 3.0 Red Hat Fedora Core5 Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.3.9 Apple Mac OS X Server 10.3.8 Apple Mac OS X Server 10.3.7 Apple Mac OS X Server 10.3.6 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.3 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.3.9 Apple Mac OS X 10.3.8 Apple Mac OS X 10.3.7 Apple Mac OS X 10.3.6 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 |
| Not Vulnerable: |
SquirrelMail SquirrelMail 1.4.9 a |
Discussion
SquirrelMail Multiple Cross Site Scripting and Input Validation Vulnerabilities
SquirrelMail is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to SquirrelMail 1.4.9a are vulnerable.
SquirrelMail is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to SquirrelMail 1.4.9a are vulnerable.
Exploit / POC
SquirrelMail Multiple Cross Site Scripting and Input Validation Vulnerabilities
An attacker can exploit this vulnerability via a web client.
An attacker can exploit this vulnerability via a web client.
Solution / Fix
SquirrelMail Multiple Cross Site Scripting and Input Validation Vulnerabilities
Solution:
The vendor has released a fix to address this issue.
Please see the referenced advisories for more information.
SquirrelMail SquirrelMail 1.4.4
SquirrelMail SquirrelMail 1.4.6
SquirrelMail SquirrelMail 1.4.7
SquirrelMail SquirrelMail 1.4.8
Apple Mac OS X Server 10.3.9
Apple Mac OS X 10.4.10
Apple Mac OS X Server 10.4.10
Solution:
The vendor has released a fix to address this issue.
Please see the referenced advisories for more information.
SquirrelMail SquirrelMail 1.4.4
-
Debian squirrelmail_1.4.4-10_all.deb
http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelma il_1.4.4-10_all.deb
SquirrelMail SquirrelMail 1.4.6
-
RedHat squirrelmail-1.4.8-3.fc5.noarch.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat squirrelmail-1.4.8-3.fc5.src.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
SquirrelMail SquirrelMail 1.4.7
-
SquirrelMail SquirrelMail Release 1.4.9a
http://sourceforge.net/project/shownotes.php?release_id=468482
SquirrelMail SquirrelMail 1.4.8
-
Mandriva /squirrelmail-ar-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ar-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-bg-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-bg-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-bn-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-bn-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ca-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ca-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-cs-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-cs-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-cy-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-cy-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-cyrus-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-cyrus-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-da-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-da-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-de-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-de-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-el-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-el-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-en-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-en-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-es-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-es-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-et-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-et-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-eu-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-eu-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-fa-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-fa-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-fi-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-fi-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-fo-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-fo-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-fr-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-fr-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-he-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-he-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-hr-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-hr-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-hu-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-hu-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-id-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-is-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-is-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-it-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-it-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ja-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ja-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ka-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ka-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ko-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ko-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-lt-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-lt-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ms-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ms-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-nb-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-nb-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-nl-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-nl-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-nn-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-nn-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-pl-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-pl-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-poutils-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-poutils-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-pt-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-pt-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ro-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ro-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ru-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ru-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-sk-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-sk-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-sl-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-sl-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-sr-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-sr-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-sv-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-sv-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-th-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-th-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-tl-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-tl-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-tr-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-tr-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ug-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ug-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-uk-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-uk-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-vi-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-vi-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-zh_CN-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-zh_CN-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-zh_TW-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-zh_TW-1.4.8-3.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2007-007Pan.dmg For Mac OS X Server v10.3.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.4.10
-
Apple SecUpd2007-007Ti.dmg For Mac OS X v10.4.10 (PowerPC)
http://www.apple.com/support/downloads/ -
Apple SecUpd2007-007Univ.dmg For Mac OS X v10.4.10 (Universal)
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.10
-
Apple SecUpdSrvr2007-007Ti.dmg For Mac OS X Server v10.4.10 (PowerPC)
http://www.apple.com/support/downloads/ -
Apple SecUpdSrvr2007-007Universal.dmg For Mac OS X Server v10.4.10 (Universal)
http://www.apple.com/support/downloads/
References
SquirrelMail Multiple Cross Site Scripting and Input Validation Vulnerabilities
References:
References:
- Vendor Homepage (SquirrelMail)
- Cross site scripting in compose, draft & HTML mail viewing (SquirrelMail)
- RHSA-2007:0022-3 - squirrelmail security update (Red Hat)