SquirrelMail Multiple Cross Site Scripting Vulnerabilities
BID:23910
Info
SquirrelMail Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 23910 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-1262 CVE-2007-2589 |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2007 12:00AM |
| Updated: | Aug 02 2007 12:05AM |
| Credit: | Mikhail Markin, Tomas Kuliavas and Michael Jordon are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
SquirrelMail SquirrelMail 1.4.9 a SquirrelMail SquirrelMail 1.4.8 SquirrelMail SquirrelMail 1.4.7 SquirrelMail SquirrelMail 1.4.6 -rc1 SquirrelMail SquirrelMail 1.4.6 -cvs SquirrelMail SquirrelMail 1.4.6 SquirrelMail SquirrelMail 1.4.5 SquirrelMail SquirrelMail 1.4.4 RC1 SquirrelMail SquirrelMail 1.4.4 SquirrelMail SquirrelMail 1.4.3 RC1 SquirrelMail SquirrelMail 1.4.3 r3 SquirrelMail SquirrelMail 1.4.3 a SquirrelMail SquirrelMail 1.4.3 SquirrelMail SquirrelMail 1.4.2 SquirrelMail SquirrelMail 1.4.1 SquirrelMail SquirrelMail 1.4 RC1 SquirrelMail SquirrelMail 1.4 SquirrelMail SquirelMail 1.4.10 SquirrelMail SquirelMail 1.4.10a SGI ProPack 3.0 SP6 rPath rPath Linux 1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.3.9 Apple Mac OS X Server 10.3.8 Apple Mac OS X Server 10.3.7 Apple Mac OS X Server 10.3.6 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.3 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.3.9 Apple Mac OS X 10.3.8 Apple Mac OS X 10.3.7 Apple Mac OS X 10.3.6 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 |
| Not Vulnerable: | |
Discussion
SquirrelMail Multiple Cross Site Scripting Vulnerabilities
SquirrelMail is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials and to launch other attacks.
SquirrelMail is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploit / POC
SquirrelMail Multiple Cross Site Scripting Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
SquirrelMail Multiple Cross Site Scripting Vulnerabilities
Solution:
The vendor has released a fix to address these issues. Please see the referenced advisories for more information.
SquirrelMail SquirelMail 1.4.10a
SquirrelMail SquirelMail 1.4.10
SquirrelMail SquirrelMail 1.4.4
SquirrelMail SquirrelMail 1.4.8
SquirrelMail SquirrelMail 1.4.9 a
Apple Mac OS X Server 10.3.9
Apple Mac OS X 10.3.9
Apple Mac OS X 10.4.10
Apple Mac OS X Server 10.4.10
MandrakeSoft Corporate Server 3.0
MandrakeSoft Corporate Server 3.0 x86_64
Solution:
The vendor has released a fix to address these issues. Please see the referenced advisories for more information.
SquirrelMail SquirelMail 1.4.10a
-
SquirrelMail 1.4.10-1.4.10a.patch
http://www.squirrelmail.org/patches/1.4.10-security/1.4.10-1.4.10a.pat ch
SquirrelMail SquirelMail 1.4.10
-
SquirrelMail 1.4.10-1.4.10a.patch
http://www.squirrelmail.org/patches/1.4.10-security/1.4.10-1.4.10a.pat ch
SquirrelMail SquirrelMail 1.4.4
-
Debian squirrelmail_1.4.4-11_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelma il_1.4.4-11_all.deb -
Debian squirrelmail_1.4.9a-2_all.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelma il_1.4.9a-2_all.deb
SquirrelMail SquirrelMail 1.4.8
-
Mandriva squirrelmail-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ar-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ar-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-bg-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-bg-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-bn-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-bn-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ca-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ca-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-cs-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-cs-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-cy-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-cy-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-cyrus-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-cyrus-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-da-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-da-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-de-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-de-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-el-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-el-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-en-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-en-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-es-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-es-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-et-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-et-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-eu-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-eu-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-fa-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-fa-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-fi-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-fi-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-fo-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-fo-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-fr-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-fr-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-he-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-he-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-hr-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-hr-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-hu-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-hu-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-id-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-id-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-is-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-is-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-it-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-it-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ja-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ja-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ka-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ka-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ko-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ko-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-lt-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-lt-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ms-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ms-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-nb-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-nb-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-nl-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-nl-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-nn-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-nn-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-pl-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-pl-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-poutils-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-poutils-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-pt-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-pt-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ro-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ro-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ru-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ru-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-sk-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-sk-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-sl-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-sl-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-sr-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-sr-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-sv-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-sv-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-th-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-th-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-tl-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-tl-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-tr-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-tr-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ug-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-ug-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-uk-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-uk-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-vi-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-vi-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-zh_CN-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-zh_CN-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-zh_TW-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-zh_TW-1.4.10a-0.1.20060mlcs4.noarch.rpm
Corporate 4.0:
http://www.mandriva.com/en/download
SquirrelMail SquirrelMail 1.4.9 a
-
SquirrelMail 1.4.9a.patch
http://www.squirrelmail.org/patches/1.4.10-security/1.4.9a.patch
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2007-007Pan.dmg For Mac OS X Server v10.3.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.3.9
-
Apple SecUpd2007-007Pan.dmg For Mac OS X v10.3.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.4.10
-
Apple SecUpd2007-007Ti.dmg For Mac OS X v10.4.10 (PowerPC)
http://www.apple.com/support/downloads/ -
Apple SecUpd2007-007Univ.dmg For Mac OS X v10.4.10 (Universal)
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.10
-
Apple SecUpdSrvr2007-007Ti.dmg For Mac OS X Server v10.4.10 (PowerPC)
http://www.apple.com/support/downloads/ -
Apple SecUpdSrvr2007-007Universal.dmg For Mac OS X Server v10.4.10 (Universal)
http://www.apple.com/support/downloads/
MandrakeSoft Corporate Server 3.0
-
Mandriva squirrelmail-1.4.5-1.6.C30mdk.noarch.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-poutils-1.4.5-1.6.C30mdk.noarch.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
MandrakeSoft Corporate Server 3.0 x86_64
-
Mandriva squirrelmail-1.4.5-1.6.C30mdk.noarch.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-poutils-1.4.5-1.6.C30mdk.noarch.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download
References
SquirrelMail Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Cross site scripting in HTML filter (SquirrelMail)
- Vendor Homepage (SquirrelMail)
- RHSA-2007:0358-2 squirrelmail security update (Red Hat)