SquirrelMail kayıtları
squirrelmail üreticisine ait 76 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %1,3
- Pre-auth RCE
- 18
- Düzeltme kaydı olan
- %64,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')14
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-502 Deserialization of Untrusted Data2
- CWE-287 Improper Authentication2
- CWE-20 Improper Input Validation2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
76 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2017-7692Kavram kanıtı | SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file thsquirrelmail · squirrelmail · CWE-20 | Yüksek8,8 | — | %32,2 | 20 Nis 2017 |
43Planlayın | CVE-2006-2842Kavram kanıtı | PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_squirrelmail · squirrelmail | Yüksek7,5 | — | %44,0 | 6 Haz 2006 |
43Planlayın | CVE-2002-0516Kavram kanıtı | SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cosquirrelmail · squirrelmail | Kritik10,0 | — | %11,0 | 12 Ağu 2002 |
41Planlayın | CVE-2004-0521İstismar yok | SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown imsquirrelmail · squirrelmail | Kritik10,0 | — | %3,2 | 18 Ağu 2004 |
40Planlayın | CVE-2005-1924Kavram kanıtı | The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharactsquirrelmail · gpg plugin | Kritik9,3 | — | %10,3 | 31 Ara 2005 |
39İzleyin | CVE-2003-0990Silahlaştırılmış | The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters squirrelmail · gpg plugin | Yüksek7,5 | — | %28,8 | 20 Oca 2004 |
39İzleyin | CVE-2020-14932İstismar yok | compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request.squirrelmail · squirrelmail · CWE-502 | Kritik9,8 | — | %1,4 | 20 Haz 2020 |
38İzleyin | CVE-2002-1131Kavram kanıtı | Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) squirrelmail · squirrelmail | Yüksek7,5 | — | %25,8 | 4 Eki 2002 |
36İzleyin | CVE-2018-8741İstismar yok | A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hostsquirrelmail · squirrelmail · CWE-22 | Yüksek8,8 | — | %4,2 | 17 Mar 2018 |
35İzleyin | CVE-2020-14933İstismar yok | compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request.squirrelmail · squirrelmail · CWE-502 | Yüksek8,8 | — | %1,4 | 20 Haz 2020 |
34İzleyin | CVE-2004-0519Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users squirrelmail · squirrelmail | Orta6,8 | — | %22,5 | 18 Ağu 2004 |
31İzleyin | CVE-2005-0239İstismar yok | viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharactersquirrelmail · s mime plugin | Yüksek7,5 | — | %4,2 | 2 May 2005 |
31İzleyin | CVE-2001-1159İstismar yok | load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allowssquirrelmail · squirrelmail | Yüksek7,5 | — | %3,6 | 2 Tem 2001 |
31İzleyin | CVE-2005-0152İstismar yok | PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."squirrelmail · squirrelmail | Yüksek7,5 | — | %3,6 | 2 Şub 2005 |
31İzleyin | CVE-2002-1650İstismar yok | The spell checker plugin (check_me.mod.php) for SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary commands via a modifisquirrelmail · squirrelmail | Yüksek7,5 | — | %3,5 | 31 Ara 2002 |
31İzleyin | CVE-2002-1648İstismar yok | Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other usquirrelmail · squirrelmail | Yüksek7,5 | — | %3,4 | 31 Ara 2002 |
31İzleyin | CVE-2007-3636Kavram kanıtı | Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands viasquirrelmail · gpg plugin | Yüksek7,5 | — | %3,1 | 9 Tem 2007 |
31İzleyin | CVE-2007-3778İstismar yok | The G/PGP (GPG) Plugin 2.0, and 2.1dev before 20060912, for Squirrelmail allows remote attackers to execute arbitrary commands via shell metsquirrelmail · gpg plugin | Yüksek7,5 | — | %2,7 | 15 Tem 2007 |
31İzleyin | CVE-2005-0103İstismar yok | PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code bysquirrelmail · squirrelmail · CWE-94 | Yüksek7,5 | — | %2,3 | 24 Oca 2005 |
30İzleyin | CVE-2007-2631İstismar yok | Cross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actiosquirrelmail · squirrelmail | Yüksek7,5 | — | %1,4 | 13 May 2007 |
30İzleyin | CVE-2012-5623İstismar yok | Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.squirrelmail · change passwd · CWE-327 | Yüksek7,5 | — | %0,7 | 13 Şub 2020 |
29İzleyin | CVE-2004-0520Kavram kanıtı | Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and scrisquirrelmail · squirrelmail | Orta6,8 | — | %7,1 | 18 Ağu 2004 |
29İzleyin | CVE-2004-0639Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or scsquirrelmail · squirrelmail | Orta6,8 | — | %6,0 | 6 Ağu 2004 |
28İzleyin | CVE-2006-4019Kavram kanıtı | Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary progrsquirrelmail · squirrelmail | Orta6,4 | — | %10,0 | 11 Ağu 2006 |
28İzleyin | CVE-2007-6348İstismar yok | SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse thasquirrelmail · squirrelmail · CWE-94 | Orta6,8 | — | %3,9 | 14 Ara 2007 |
- CVE-2017-769245Planlayın
SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file th
YüksekCVSS 8,8Kavram kanıtıEPSS %32squirrelmail · squirrelmail20 Nis 2017
- CVE-2006-284243Planlayın
PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_
YüksekCVSS 7,5Kavram kanıtıEPSS %44squirrelmail · squirrelmail6 Haz 2006
- CVE-2002-051643Planlayın
SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a co
KritikCVSS 10,0Kavram kanıtıEPSS %11squirrelmail · squirrelmail12 Ağu 2002
- CVE-2004-052141Planlayın
SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown im
KritikCVSS 10,0İstismar yokEPSS %3squirrelmail · squirrelmail18 Ağu 2004
- CVE-2005-192440Planlayın
The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharact
KritikCVSS 9,3Kavram kanıtıEPSS %10squirrelmail · gpg plugin31 Ara 2005
- CVE-2003-099039İzleyin
The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters
YüksekCVSS 7,5SilahlaştırılmışEPSS %29squirrelmail · gpg plugin20 Oca 2004
- CVE-2020-1493239İzleyin
compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request.
KritikCVSS 9,8İstismar yokEPSS %1squirrelmail · squirrelmail20 Haz 2020
- CVE-2002-113138İzleyin
Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1)
YüksekCVSS 7,5Kavram kanıtıEPSS %26squirrelmail · squirrelmail4 Eki 2002
- CVE-2018-874136İzleyin
A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the host
YüksekCVSS 8,8İstismar yokEPSS %4squirrelmail · squirrelmail17 Mar 2018
- CVE-2020-1493335İzleyin
compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request.
YüksekCVSS 8,8İstismar yokEPSS %1squirrelmail · squirrelmail20 Haz 2020
- CVE-2004-051934İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users
OrtaCVSS 6,8Kavram kanıtıEPSS %23squirrelmail · squirrelmail18 Ağu 2004
- CVE-2005-023931İzleyin
viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacter
YüksekCVSS 7,5İstismar yokEPSS %4squirrelmail · s mime plugin2 May 2005
- CVE-2001-115931İzleyin
load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows
YüksekCVSS 7,5İstismar yokEPSS %4squirrelmail · squirrelmail2 Tem 2001
- CVE-2005-015231İzleyin
PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."
YüksekCVSS 7,5İstismar yokEPSS %4squirrelmail · squirrelmail2 Şub 2005
- CVE-2002-165031İzleyin
The spell checker plugin (check_me.mod.php) for SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary commands via a modifi
YüksekCVSS 7,5İstismar yokEPSS %4squirrelmail · squirrelmail31 Ara 2002
- CVE-2002-164831İzleyin
Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other u
YüksekCVSS 7,5İstismar yokEPSS %3squirrelmail · squirrelmail31 Ara 2002
- CVE-2007-363631İzleyin
Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via
YüksekCVSS 7,5Kavram kanıtıEPSS %3squirrelmail · gpg plugin9 Tem 2007
- CVE-2007-377831İzleyin
The G/PGP (GPG) Plugin 2.0, and 2.1dev before 20060912, for Squirrelmail allows remote attackers to execute arbitrary commands via shell met
YüksekCVSS 7,5İstismar yokEPSS %3squirrelmail · gpg plugin15 Tem 2007
- CVE-2005-010331İzleyin
PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by
YüksekCVSS 7,5İstismar yokEPSS %2squirrelmail · squirrelmail24 Oca 2005
- CVE-2007-263130İzleyin
Cross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actio
YüksekCVSS 7,5İstismar yokEPSS %1squirrelmail · squirrelmail13 May 2007
- CVE-2012-562330İzleyin
Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.
YüksekCVSS 7,5İstismar yokEPSS %1squirrelmail · change passwd13 Şub 2020
- CVE-2004-052029İzleyin
Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and scri
OrtaCVSS 6,8Kavram kanıtıEPSS %7squirrelmail · squirrelmail18 Ağu 2004
- CVE-2004-063929İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or sc
OrtaCVSS 6,8Kavram kanıtıEPSS %6squirrelmail · squirrelmail6 Ağu 2004
- CVE-2006-401928İzleyin
Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary progr
OrtaCVSS 6,4Kavram kanıtıEPSS %10squirrelmail · squirrelmail11 Ağu 2006
- CVE-2007-634828İzleyin
SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse tha
OrtaCVSS 6,8İstismar yokEPSS %4squirrelmail · squirrelmail14 Ara 2007