SquirrelMail Multiple HTML injection, cross-site scripting, and Security Restriction Bypass Vulnerability
Release date:
Updated on:
Affected Systems:
SquirrelMail 1.4.x
SquirrelMail 1.2.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 48648
Cve id: CVE-2010-4554, CVE-2010-4555, CVE-2011-2023
SquirrelMail is a WEBMAIL program written in PHP.
SquirrelMail has multiple HTML injection, cross-site scripting, and security restriction bypass vulnerabilities. Remote attackers can exploit these vulnerabilities to execute code and steal authentication creden, controls the website appearance or bypasses certain security restrictions.
<* Source: SquirrelMail
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SquirrelMail
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.squirrelmail.org