SquirrelMail records
76 published records for vendor squirrelmail.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 1.3%
- Pre-auth RCE
- 18
- With a fix record
- 64.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')14
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-502 Deserialization of Untrusted Data2
- CWE-287 Improper Authentication2
- CWE-20 Improper Input Validation2
The weakness classes this vendor ships most often: where to look.
CWEAll records
76 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2017-7692Proof of concept | SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file thsquirrelmail · squirrelmail · CWE-20 | High8.8 | — | 32.2% | Apr 20, 2017 |
43Plan | CVE-2006-2842Proof of concept | PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_squirrelmail · squirrelmail | High7.5 | — | 44.0% | Jun 6, 2006 |
43Plan | CVE-2002-0516Proof of concept | SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cosquirrelmail · squirrelmail | Critical10.0 | — | 11.0% | Aug 12, 2002 |
41Plan | CVE-2004-0521No exploit | SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown imsquirrelmail · squirrelmail | Critical10.0 | — | 3.2% | Aug 18, 2004 |
40Plan | CVE-2005-1924Proof of concept | The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharactsquirrelmail · gpg plugin | Critical9.3 | — | 10.3% | Dec 31, 2005 |
39Monitor | CVE-2003-0990Weaponized | The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters squirrelmail · gpg plugin | High7.5 | — | 28.8% | Jan 20, 2004 |
39Monitor | CVE-2020-14932No exploit | compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request.squirrelmail · squirrelmail · CWE-502 | Critical9.8 | — | 1.4% | Jun 20, 2020 |
38Monitor | CVE-2002-1131Proof of concept | Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) squirrelmail · squirrelmail | High7.5 | — | 25.8% | Oct 4, 2002 |
36Monitor | CVE-2018-8741No exploit | A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hostsquirrelmail · squirrelmail · CWE-22 | High8.8 | — | 4.2% | Mar 17, 2018 |
35Monitor | CVE-2020-14933No exploit | compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request.squirrelmail · squirrelmail · CWE-502 | High8.8 | — | 1.4% | Jun 20, 2020 |
34Monitor | CVE-2004-0519Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users squirrelmail · squirrelmail | Medium6.8 | — | 22.5% | Aug 18, 2004 |
31Monitor | CVE-2005-0239No exploit | viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharactersquirrelmail · s mime plugin | High7.5 | — | 4.2% | May 2, 2005 |
31Monitor | CVE-2001-1159No exploit | load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allowssquirrelmail · squirrelmail | High7.5 | — | 3.6% | Jul 2, 2001 |
31Monitor | CVE-2005-0152No exploit | PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."squirrelmail · squirrelmail | High7.5 | — | 3.6% | Feb 2, 2005 |
31Monitor | CVE-2002-1650No exploit | The spell checker plugin (check_me.mod.php) for SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary commands via a modifisquirrelmail · squirrelmail | High7.5 | — | 3.5% | Dec 31, 2002 |
31Monitor | CVE-2002-1648No exploit | Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other usquirrelmail · squirrelmail | High7.5 | — | 3.4% | Dec 31, 2002 |
31Monitor | CVE-2007-3636Proof of concept | Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands viasquirrelmail · gpg plugin | High7.5 | — | 3.1% | Jul 9, 2007 |
31Monitor | CVE-2007-3778No exploit | The G/PGP (GPG) Plugin 2.0, and 2.1dev before 20060912, for Squirrelmail allows remote attackers to execute arbitrary commands via shell metsquirrelmail · gpg plugin | High7.5 | — | 2.7% | Jul 15, 2007 |
31Monitor | CVE-2005-0103No exploit | PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code bysquirrelmail · squirrelmail · CWE-94 | High7.5 | — | 2.3% | Jan 24, 2005 |
30Monitor | CVE-2007-2631No exploit | Cross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actiosquirrelmail · squirrelmail | High7.5 | — | 1.4% | May 13, 2007 |
30Monitor | CVE-2012-5623No exploit | Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.squirrelmail · change passwd · CWE-327 | High7.5 | — | 0.7% | Feb 13, 2020 |
29Monitor | CVE-2004-0520Proof of concept | Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and scrisquirrelmail · squirrelmail | Medium6.8 | — | 7.1% | Aug 18, 2004 |
29Monitor | CVE-2004-0639Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or scsquirrelmail · squirrelmail | Medium6.8 | — | 6.0% | Aug 6, 2004 |
28Monitor | CVE-2006-4019Proof of concept | Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary progrsquirrelmail · squirrelmail | Medium6.4 | — | 10.0% | Aug 11, 2006 |
28Monitor | CVE-2007-6348No exploit | SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse thasquirrelmail · squirrelmail · CWE-94 | Medium6.8 | — | 3.9% | Dec 14, 2007 |
- CVE-2017-769245Plan
SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file th
HighCVSS 8.8Proof of conceptEPSS 32%squirrelmail · squirrelmailApr 20, 2017
- CVE-2006-284243Plan
PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_
HighCVSS 7.5Proof of conceptEPSS 44%squirrelmail · squirrelmailJun 6, 2006
- CVE-2002-051643Plan
SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a co
CriticalCVSS 10.0Proof of conceptEPSS 11%squirrelmail · squirrelmailAug 12, 2002
- CVE-2004-052141Plan
SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown im
CriticalCVSS 10.0No exploitEPSS 3%squirrelmail · squirrelmailAug 18, 2004
- CVE-2005-192440Plan
The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharact
CriticalCVSS 9.3Proof of conceptEPSS 10%squirrelmail · gpg pluginDec 31, 2005
- CVE-2003-099039Monitor
The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters
HighCVSS 7.5WeaponizedEPSS 29%squirrelmail · gpg pluginJan 20, 2004
- CVE-2020-1493239Monitor
compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request.
CriticalCVSS 9.8No exploitEPSS 1%squirrelmail · squirrelmailJun 20, 2020
- CVE-2002-113138Monitor
Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1)
HighCVSS 7.5Proof of conceptEPSS 26%squirrelmail · squirrelmailOct 4, 2002
- CVE-2018-874136Monitor
A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the host
HighCVSS 8.8No exploitEPSS 4%squirrelmail · squirrelmailMar 17, 2018
- CVE-2020-1493335Monitor
compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request.
HighCVSS 8.8No exploitEPSS 1%squirrelmail · squirrelmailJun 20, 2020
- CVE-2004-051934Monitor
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users
MediumCVSS 6.8Proof of conceptEPSS 23%squirrelmail · squirrelmailAug 18, 2004
- CVE-2005-023931Monitor
viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacter
HighCVSS 7.5No exploitEPSS 4%squirrelmail · s mime pluginMay 2, 2005
- CVE-2001-115931Monitor
load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows
HighCVSS 7.5No exploitEPSS 4%squirrelmail · squirrelmailJul 2, 2001
- CVE-2005-015231Monitor
PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."
HighCVSS 7.5No exploitEPSS 4%squirrelmail · squirrelmailFeb 2, 2005
- CVE-2002-165031Monitor
The spell checker plugin (check_me.mod.php) for SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary commands via a modifi
HighCVSS 7.5No exploitEPSS 4%squirrelmail · squirrelmailDec 31, 2002
- CVE-2002-164831Monitor
Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other u
HighCVSS 7.5No exploitEPSS 3%squirrelmail · squirrelmailDec 31, 2002
- CVE-2007-363631Monitor
Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via
HighCVSS 7.5Proof of conceptEPSS 3%squirrelmail · gpg pluginJul 9, 2007
- CVE-2007-377831Monitor
The G/PGP (GPG) Plugin 2.0, and 2.1dev before 20060912, for Squirrelmail allows remote attackers to execute arbitrary commands via shell met
HighCVSS 7.5No exploitEPSS 3%squirrelmail · gpg pluginJul 15, 2007
- CVE-2005-010331Monitor
PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by
HighCVSS 7.5No exploitEPSS 2%squirrelmail · squirrelmailJan 24, 2005
- CVE-2007-263130Monitor
Cross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actio
HighCVSS 7.5No exploitEPSS 1%squirrelmail · squirrelmailMay 13, 2007
- CVE-2012-562330Monitor
Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.
HighCVSS 7.5No exploitEPSS 1%squirrelmail · change passwdFeb 13, 2020
- CVE-2004-052029Monitor
Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and scri
MediumCVSS 6.8Proof of conceptEPSS 7%squirrelmail · squirrelmailAug 18, 2004
- CVE-2004-063929Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or sc
MediumCVSS 6.8Proof of conceptEPSS 6%squirrelmail · squirrelmailAug 6, 2004
- CVE-2006-401928Monitor
Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary progr
MediumCVSS 6.4Proof of conceptEPSS 10%squirrelmail · squirrelmailAug 11, 2006
- CVE-2007-634828Monitor
SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse tha
MediumCVSS 6.8No exploitEPSS 4%squirrelmail · squirrelmailDec 14, 2007