Перейти к содержимому
Noroxi

Записи SquirrelMail

76 опубликованных записей вендора squirrelmail.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 1,3 %
Pre-auth RCE
18
С записью об исправлении
64,5 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

76 записей
  • CVE-2017-7692
    45В плане

    SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file th

    ВысокаяCVSS 8,8Proof of conceptEPSS 32 %

    squirrelmail · squirrelmail20 апр. 2017 г.

  • CVE-2006-2842
    43В плане

    PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_

    ВысокаяCVSS 7,5Proof of conceptEPSS 44 %

    squirrelmail · squirrelmail6 июн. 2006 г.

  • CVE-2002-0516
    43В плане

    SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a co

    КритическаяCVSS 10,0Proof of conceptEPSS 11 %

    squirrelmail · squirrelmail12 авг. 2002 г.

  • CVE-2004-0521
    41В плане

    SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown im

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    squirrelmail · squirrelmail18 авг. 2004 г.

  • CVE-2005-1924
    40В плане

    The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharact

    КритическаяCVSS 9,3Proof of conceptEPSS 10 %

    squirrelmail · gpg plugin31 дек. 2005 г.

  • CVE-2003-0990
    39Наблюдать

    The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 29 %

    squirrelmail · gpg plugin20 янв. 2004 г.

  • CVE-2020-14932
    39Наблюдать

    compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    squirrelmail · squirrelmail20 июн. 2020 г.

  • CVE-2002-1131
    38Наблюдать

    Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1)

    ВысокаяCVSS 7,5Proof of conceptEPSS 26 %

    squirrelmail · squirrelmail4 окт. 2002 г.

  • CVE-2018-8741
    36Наблюдать

    A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the host

    ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %

    squirrelmail · squirrelmail17 мар. 2018 г.

  • CVE-2020-14933
    35Наблюдать

    compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    squirrelmail · squirrelmail20 июн. 2020 г.

  • CVE-2004-0519
    34Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users

    СредняяCVSS 6,8Proof of conceptEPSS 23 %

    squirrelmail · squirrelmail18 авг. 2004 г.

  • CVE-2005-0239
    31Наблюдать

    viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacter

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    squirrelmail · s mime plugin2 мая 2005 г.

  • CVE-2001-1159
    31Наблюдать

    load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    squirrelmail · squirrelmail2 июл. 2001 г.

  • CVE-2005-0152
    31Наблюдать

    PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    squirrelmail · squirrelmail2 февр. 2005 г.

  • CVE-2002-1650
    31Наблюдать

    The spell checker plugin (check_me.mod.php) for SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary commands via a modifi

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    squirrelmail · squirrelmail31 дек. 2002 г.

  • CVE-2002-1648
    31Наблюдать

    Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other u

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    squirrelmail · squirrelmail31 дек. 2002 г.

  • CVE-2007-3636
    31Наблюдать

    Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    squirrelmail · gpg plugin9 июл. 2007 г.

  • CVE-2007-3778
    31Наблюдать

    The G/PGP (GPG) Plugin 2.0, and 2.1dev before 20060912, for Squirrelmail allows remote attackers to execute arbitrary commands via shell met

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    squirrelmail · gpg plugin15 июл. 2007 г.

  • CVE-2005-0103
    31Наблюдать

    PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    squirrelmail · squirrelmail24 янв. 2005 г.

  • CVE-2007-2631
    30Наблюдать

    Cross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actio

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    squirrelmail · squirrelmail13 мая 2007 г.

  • CVE-2012-5623
    30Наблюдать

    Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    squirrelmail · change passwd13 февр. 2020 г.

  • CVE-2004-0520
    29Наблюдать

    Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and scri

    СредняяCVSS 6,8Proof of conceptEPSS 7 %

    squirrelmail · squirrelmail18 авг. 2004 г.

  • CVE-2004-0639
    29Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or sc

    СредняяCVSS 6,8Proof of conceptEPSS 6 %

    squirrelmail · squirrelmail6 авг. 2004 г.

  • CVE-2006-4019
    28Наблюдать

    Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary progr

    СредняяCVSS 6,4Proof of conceptEPSS 10 %

    squirrelmail · squirrelmail11 авг. 2006 г.

  • CVE-2007-6348
    28Наблюдать

    SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse tha

    СредняяCVSS 6,8Эксплойта нетEPSS 4 %

    squirrelmail · squirrelmail14 дек. 2007 г.