Revision
7906 -
Directory Listing
-
[select for diffs]
Modified
Sat May 16 15:31:38 2009 UTC
(14 years, 10 months ago)
by
laffer1
Diff to
previous 7184
,
to
selected 2286
functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message.
Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie
The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).
Revision
2286 -
Directory Listing
-
[selected]
Modified
Tue Aug 14 05:50:23 2007 UTC
(16 years, 7 months ago)
by
laffer1
Diff to
previous 1793
Update squirrelmail to 1.4.10a. This is a security update.