Skip to content
Noroxi

SquirrelMail records

76 published records for vendor squirrelmail.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 1.3%
Pre-auth RCE
18
With a fix record
64.5%
Median publish → KEV
No record has entered KEV

All records

76 records
  • SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file th

    HighCVSS 8.8Proof of conceptEPSS 32%

    squirrelmail · squirrelmailApr 20, 2017

  • PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_

    HighCVSS 7.5Proof of conceptEPSS 44%

    squirrelmail · squirrelmailJun 6, 2006

  • SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a co

    CriticalCVSS 10.0Proof of conceptEPSS 11%

    squirrelmail · squirrelmailAug 12, 2002

  • SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown im

    CriticalCVSS 10.0No exploitEPSS 3%

    squirrelmail · squirrelmailAug 18, 2004

  • The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharact

    CriticalCVSS 9.3Proof of conceptEPSS 10%

    squirrelmail · gpg pluginDec 31, 2005

  • CVE-2003-0990
    39Monitor

    The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters

    HighCVSS 7.5WeaponizedEPSS 29%

    squirrelmail · gpg pluginJan 20, 2004

  • compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request.

    CriticalCVSS 9.8No exploitEPSS 1%

    squirrelmail · squirrelmailJun 20, 2020

  • CVE-2002-1131
    38Monitor

    Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1)

    HighCVSS 7.5Proof of conceptEPSS 26%

    squirrelmail · squirrelmailOct 4, 2002

  • CVE-2018-8741
    36Monitor

    A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the host

    HighCVSS 8.8No exploitEPSS 4%

    squirrelmail · squirrelmailMar 17, 2018

  • compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request.

    HighCVSS 8.8No exploitEPSS 1%

    squirrelmail · squirrelmailJun 20, 2020

  • CVE-2004-0519
    34Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users

    MediumCVSS 6.8Proof of conceptEPSS 23%

    squirrelmail · squirrelmailAug 18, 2004

  • CVE-2005-0239
    31Monitor

    viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacter

    HighCVSS 7.5No exploitEPSS 4%

    squirrelmail · s mime pluginMay 2, 2005

  • CVE-2001-1159
    31Monitor

    load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows

    HighCVSS 7.5No exploitEPSS 4%

    squirrelmail · squirrelmailJul 2, 2001

  • CVE-2005-0152
    31Monitor

    PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."

    HighCVSS 7.5No exploitEPSS 4%

    squirrelmail · squirrelmailFeb 2, 2005

  • CVE-2002-1650
    31Monitor

    The spell checker plugin (check_me.mod.php) for SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary commands via a modifi

    HighCVSS 7.5No exploitEPSS 4%

    squirrelmail · squirrelmailDec 31, 2002

  • CVE-2002-1648
    31Monitor

    Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other u

    HighCVSS 7.5No exploitEPSS 3%

    squirrelmail · squirrelmailDec 31, 2002

  • CVE-2007-3636
    31Monitor

    Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via

    HighCVSS 7.5Proof of conceptEPSS 3%

    squirrelmail · gpg pluginJul 9, 2007

  • CVE-2007-3778
    31Monitor

    The G/PGP (GPG) Plugin 2.0, and 2.1dev before 20060912, for Squirrelmail allows remote attackers to execute arbitrary commands via shell met

    HighCVSS 7.5No exploitEPSS 3%

    squirrelmail · gpg pluginJul 15, 2007

  • CVE-2005-0103
    31Monitor

    PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by

    HighCVSS 7.5No exploitEPSS 2%

    squirrelmail · squirrelmailJan 24, 2005

  • CVE-2007-2631
    30Monitor

    Cross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actio

    HighCVSS 7.5No exploitEPSS 1%

    squirrelmail · squirrelmailMay 13, 2007

  • CVE-2012-5623
    30Monitor

    Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.

    HighCVSS 7.5No exploitEPSS 1%

    squirrelmail · change passwdFeb 13, 2020

  • CVE-2004-0520
    29Monitor

    Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and scri

    MediumCVSS 6.8Proof of conceptEPSS 7%

    squirrelmail · squirrelmailAug 18, 2004

  • CVE-2004-0639
    29Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or sc

    MediumCVSS 6.8Proof of conceptEPSS 6%

    squirrelmail · squirrelmailAug 6, 2004

  • CVE-2006-4019
    28Monitor

    Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary progr

    MediumCVSS 6.4Proof of conceptEPSS 10%

    squirrelmail · squirrelmailAug 11, 2006

  • CVE-2007-6348
    28Monitor

    SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse tha

    MediumCVSS 6.8No exploitEPSS 4%

    squirrelmail · squirrelmailDec 14, 2007