Записи SquirrelMail
76 опубликованных записей вендора squirrelmail.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 1,3 %
- Pre-auth RCE
- 18
- С записью об исправлении
- 64,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')14
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-502 Deserialization of Untrusted Data2
- CWE-287 Improper Authentication2
- CWE-20 Improper Input Validation2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
76 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2017-7692Proof of concept | SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file thsquirrelmail · squirrelmail · CWE-20 | Высокая8,8 | — | 32,2 % | 20 апр. 2017 г. |
43В плане | CVE-2006-2842Proof of concept | PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_squirrelmail · squirrelmail | Высокая7,5 | — | 44,0 % | 6 июн. 2006 г. |
43В плане | CVE-2002-0516Proof of concept | SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cosquirrelmail · squirrelmail | Критическая10,0 | — | 11,0 % | 12 авг. 2002 г. |
41В плане | CVE-2004-0521Эксплойта нет | SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown imsquirrelmail · squirrelmail | Критическая10,0 | — | 3,2 % | 18 авг. 2004 г. |
40В плане | CVE-2005-1924Proof of concept | The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharactsquirrelmail · gpg plugin | Критическая9,3 | — | 10,3 % | 31 дек. 2005 г. |
39Наблюдать | CVE-2003-0990Готовый эксплойт | The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters squirrelmail · gpg plugin | Высокая7,5 | — | 28,8 % | 20 янв. 2004 г. |
39Наблюдать | CVE-2020-14932Эксплойта нет | compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request.squirrelmail · squirrelmail · CWE-502 | Критическая9,8 | — | 1,4 % | 20 июн. 2020 г. |
38Наблюдать | CVE-2002-1131Proof of concept | Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) squirrelmail · squirrelmail | Высокая7,5 | — | 25,8 % | 4 окт. 2002 г. |
36Наблюдать | CVE-2018-8741Эксплойта нет | A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hostsquirrelmail · squirrelmail · CWE-22 | Высокая8,8 | — | 4,2 % | 17 мар. 2018 г. |
35Наблюдать | CVE-2020-14933Эксплойта нет | compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request.squirrelmail · squirrelmail · CWE-502 | Высокая8,8 | — | 1,4 % | 20 июн. 2020 г. |
34Наблюдать | CVE-2004-0519Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users squirrelmail · squirrelmail | Средняя6,8 | — | 22,5 % | 18 авг. 2004 г. |
31Наблюдать | CVE-2005-0239Эксплойта нет | viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharactersquirrelmail · s mime plugin | Высокая7,5 | — | 4,2 % | 2 мая 2005 г. |
31Наблюдать | CVE-2001-1159Эксплойта нет | load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allowssquirrelmail · squirrelmail | Высокая7,5 | — | 3,6 % | 2 июл. 2001 г. |
31Наблюдать | CVE-2005-0152Эксплойта нет | PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."squirrelmail · squirrelmail | Высокая7,5 | — | 3,6 % | 2 февр. 2005 г. |
31Наблюдать | CVE-2002-1650Эксплойта нет | The spell checker plugin (check_me.mod.php) for SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary commands via a modifisquirrelmail · squirrelmail | Высокая7,5 | — | 3,5 % | 31 дек. 2002 г. |
31Наблюдать | CVE-2002-1648Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other usquirrelmail · squirrelmail | Высокая7,5 | — | 3,4 % | 31 дек. 2002 г. |
31Наблюдать | CVE-2007-3636Proof of concept | Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands viasquirrelmail · gpg plugin | Высокая7,5 | — | 3,1 % | 9 июл. 2007 г. |
31Наблюдать | CVE-2007-3778Эксплойта нет | The G/PGP (GPG) Plugin 2.0, and 2.1dev before 20060912, for Squirrelmail allows remote attackers to execute arbitrary commands via shell metsquirrelmail · gpg plugin | Высокая7,5 | — | 2,7 % | 15 июл. 2007 г. |
31Наблюдать | CVE-2005-0103Эксплойта нет | PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code bysquirrelmail · squirrelmail · CWE-94 | Высокая7,5 | — | 2,3 % | 24 янв. 2005 г. |
30Наблюдать | CVE-2007-2631Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actiosquirrelmail · squirrelmail | Высокая7,5 | — | 1,4 % | 13 мая 2007 г. |
30Наблюдать | CVE-2012-5623Эксплойта нет | Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.squirrelmail · change passwd · CWE-327 | Высокая7,5 | — | 0,7 % | 13 февр. 2020 г. |
29Наблюдать | CVE-2004-0520Proof of concept | Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and scrisquirrelmail · squirrelmail | Средняя6,8 | — | 7,1 % | 18 авг. 2004 г. |
29Наблюдать | CVE-2004-0639Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or scsquirrelmail · squirrelmail | Средняя6,8 | — | 6,0 % | 6 авг. 2004 г. |
28Наблюдать | CVE-2006-4019Proof of concept | Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary progrsquirrelmail · squirrelmail | Средняя6,4 | — | 10,0 % | 11 авг. 2006 г. |
28Наблюдать | CVE-2007-6348Эксплойта нет | SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse thasquirrelmail · squirrelmail · CWE-94 | Средняя6,8 | — | 3,9 % | 14 дек. 2007 г. |
- CVE-2017-769245В плане
SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file th
ВысокаяCVSS 8,8Proof of conceptEPSS 32 %squirrelmail · squirrelmail20 апр. 2017 г.
- CVE-2006-284243В плане
PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_
ВысокаяCVSS 7,5Proof of conceptEPSS 44 %squirrelmail · squirrelmail6 июн. 2006 г.
- CVE-2002-051643В плане
SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a co
КритическаяCVSS 10,0Proof of conceptEPSS 11 %squirrelmail · squirrelmail12 авг. 2002 г.
- CVE-2004-052141В плане
SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown im
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %squirrelmail · squirrelmail18 авг. 2004 г.
- CVE-2005-192440В плане
The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharact
КритическаяCVSS 9,3Proof of conceptEPSS 10 %squirrelmail · gpg plugin31 дек. 2005 г.
- CVE-2003-099039Наблюдать
The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters
ВысокаяCVSS 7,5Готовый эксплойтEPSS 29 %squirrelmail · gpg plugin20 янв. 2004 г.
- CVE-2020-1493239Наблюдать
compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %squirrelmail · squirrelmail20 июн. 2020 г.
- CVE-2002-113138Наблюдать
Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1)
ВысокаяCVSS 7,5Proof of conceptEPSS 26 %squirrelmail · squirrelmail4 окт. 2002 г.
- CVE-2018-874136Наблюдать
A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the host
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %squirrelmail · squirrelmail17 мар. 2018 г.
- CVE-2020-1493335Наблюдать
compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %squirrelmail · squirrelmail20 июн. 2020 г.
- CVE-2004-051934Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users
СредняяCVSS 6,8Proof of conceptEPSS 23 %squirrelmail · squirrelmail18 авг. 2004 г.
- CVE-2005-023931Наблюдать
viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacter
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %squirrelmail · s mime plugin2 мая 2005 г.
- CVE-2001-115931Наблюдать
load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %squirrelmail · squirrelmail2 июл. 2001 г.
- CVE-2005-015231Наблюдать
PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %squirrelmail · squirrelmail2 февр. 2005 г.
- CVE-2002-165031Наблюдать
The spell checker plugin (check_me.mod.php) for SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary commands via a modifi
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %squirrelmail · squirrelmail31 дек. 2002 г.
- CVE-2002-164831Наблюдать
Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other u
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %squirrelmail · squirrelmail31 дек. 2002 г.
- CVE-2007-363631Наблюдать
Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %squirrelmail · gpg plugin9 июл. 2007 г.
- CVE-2007-377831Наблюдать
The G/PGP (GPG) Plugin 2.0, and 2.1dev before 20060912, for Squirrelmail allows remote attackers to execute arbitrary commands via shell met
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %squirrelmail · gpg plugin15 июл. 2007 г.
- CVE-2005-010331Наблюдать
PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %squirrelmail · squirrelmail24 янв. 2005 г.
- CVE-2007-263130Наблюдать
Cross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actio
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %squirrelmail · squirrelmail13 мая 2007 г.
- CVE-2012-562330Наблюдать
Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %squirrelmail · change passwd13 февр. 2020 г.
- CVE-2004-052029Наблюдать
Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and scri
СредняяCVSS 6,8Proof of conceptEPSS 7 %squirrelmail · squirrelmail18 авг. 2004 г.
- CVE-2004-063929Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or sc
СредняяCVSS 6,8Proof of conceptEPSS 6 %squirrelmail · squirrelmail6 авг. 2004 г.
- CVE-2006-401928Наблюдать
Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary progr
СредняяCVSS 6,4Proof of conceptEPSS 10 %squirrelmail · squirrelmail11 авг. 2006 г.
- CVE-2007-634828Наблюдать
SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse tha
СредняяCVSS 6,8Эксплойта нетEPSS 4 %squirrelmail · squirrelmail14 дек. 2007 г.