SquirrelMail read_body.php Cross Site Scripting Vulnerability
BID:6302
Info
SquirrelMail read_body.php Cross Site Scripting Vulnerability
| Bugtraq ID: | 6302 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1341 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 03 2002 12:00AM |
| Updated: | Jul 11 2009 07:16PM |
| Credit: | The discovery of this vulnerability is credited to "euronymous" <[email protected]>. |
| Vulnerable: |
SquirrelMail SquirrelMail 1.2.10 SquirrelMail SquirrelMail 1.2.9 SquirrelMail SquirrelMail 1.2.8 SquirrelMail SquirrelMail 1.2.7 SquirrelMail SquirrelMail 1.2.6 |
| Not Vulnerable: | |
Discussion
SquirrelMail read_body.php Cross Site Scripting Vulnerability
A vulnerability has been discovered in SquirrelMail. The read_body.php script fails to adequately sanitize user-supplied parameters, making it prone to cross site scripting attacks. An attacker may be able to exploit this vulnerability to execute embedded script code in an HTML email that is read by a vulnerable client.
A vulnerability has been discovered in SquirrelMail. The read_body.php script fails to adequately sanitize user-supplied parameters, making it prone to cross site scripting attacks. An attacker may be able to exploit this vulnerability to execute embedded script code in an HTML email that is read by a vulnerable client.
Exploit / POC
SquirrelMail read_body.php Cross Site Scripting Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
SquirrelMail read_body.php Cross Site Scripting Vulnerability
Solution:
Gentoo Linux has released an advisory. Users who have installed net-mail/squirrelmail-1.2.9 and earlier are advised to update their systems by issuing the following commands:
emerge rsync
emerge squirrelmail
emerge clean
SquirrelMail SquirrelMail 1.2.6
SquirrelMail SquirrelMail 1.2.7
SquirrelMail SquirrelMail 1.2.8
Solution:
Gentoo Linux has released an advisory. Users who have installed net-mail/squirrelmail-1.2.9 and earlier are advised to update their systems by issuing the following commands:
emerge rsync
emerge squirrelmail
emerge clean
SquirrelMail SquirrelMail 1.2.6
-
Debian squirrelmail_1.2.6-1.3_all.deb
http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelma il_1.2.6-1.3_all.deb
SquirrelMail SquirrelMail 1.2.7
-
RedHat squirrelmail-1.2.10-1.noarch.rpm
ftp://updates.redhat.com/8.0/en/os/noarch/squirrelmail-1.2.10-1.noarch .rpm
SquirrelMail SquirrelMail 1.2.8
-
RedHat squirrelmail-1.2.10-1.noarch.rpm
ftp://updates.redhat.com/8.0/en/os/noarch/squirrelmail-1.2.10-1.noarch .rpm
References
SquirrelMail read_body.php Cross Site Scripting Vulnerability
References:
References:
- SquirrelMail v1.2.9 XSS bugs ("euronymous"
)