İçeriğe atla
Noroxi

SquirrelMail kayıtları

squirrelmail üreticisine ait 76 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %1,3
Pre-auth RCE
18
Düzeltme kaydı olan
%64,5
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

76 kayıt
  • CVE-2017-7692
    45Planlayın

    SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file th

    YüksekCVSS 8,8Kavram kanıtıEPSS %32

    squirrelmail · squirrelmail20 Nis 2017

  • CVE-2006-2842
    43Planlayın

    PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_

    YüksekCVSS 7,5Kavram kanıtıEPSS %44

    squirrelmail · squirrelmail6 Haz 2006

  • CVE-2002-0516
    43Planlayın

    SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a co

    KritikCVSS 10,0Kavram kanıtıEPSS %11

    squirrelmail · squirrelmail12 Ağu 2002

  • CVE-2004-0521
    41Planlayın

    SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown im

    KritikCVSS 10,0İstismar yokEPSS %3

    squirrelmail · squirrelmail18 Ağu 2004

  • CVE-2005-1924
    40Planlayın

    The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharact

    KritikCVSS 9,3Kavram kanıtıEPSS %10

    squirrelmail · gpg plugin31 Ara 2005

  • CVE-2003-0990
    39İzleyin

    The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters

    YüksekCVSS 7,5SilahlaştırılmışEPSS %29

    squirrelmail · gpg plugin20 Oca 2004

  • CVE-2020-14932
    39İzleyin

    compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request.

    KritikCVSS 9,8İstismar yokEPSS %1

    squirrelmail · squirrelmail20 Haz 2020

  • CVE-2002-1131
    38İzleyin

    Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1)

    YüksekCVSS 7,5Kavram kanıtıEPSS %26

    squirrelmail · squirrelmail4 Eki 2002

  • CVE-2018-8741
    36İzleyin

    A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the host

    YüksekCVSS 8,8İstismar yokEPSS %4

    squirrelmail · squirrelmail17 Mar 2018

  • CVE-2020-14933
    35İzleyin

    compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request.

    YüksekCVSS 8,8İstismar yokEPSS %1

    squirrelmail · squirrelmail20 Haz 2020

  • CVE-2004-0519
    34İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users

    OrtaCVSS 6,8Kavram kanıtıEPSS %23

    squirrelmail · squirrelmail18 Ağu 2004

  • CVE-2005-0239
    31İzleyin

    viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacter

    YüksekCVSS 7,5İstismar yokEPSS %4

    squirrelmail · s mime plugin2 May 2005

  • CVE-2001-1159
    31İzleyin

    load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows

    YüksekCVSS 7,5İstismar yokEPSS %4

    squirrelmail · squirrelmail2 Tem 2001

  • CVE-2005-0152
    31İzleyin

    PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."

    YüksekCVSS 7,5İstismar yokEPSS %4

    squirrelmail · squirrelmail2 Şub 2005

  • CVE-2002-1650
    31İzleyin

    The spell checker plugin (check_me.mod.php) for SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary commands via a modifi

    YüksekCVSS 7,5İstismar yokEPSS %4

    squirrelmail · squirrelmail31 Ara 2002

  • CVE-2002-1648
    31İzleyin

    Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other u

    YüksekCVSS 7,5İstismar yokEPSS %3

    squirrelmail · squirrelmail31 Ara 2002

  • CVE-2007-3636
    31İzleyin

    Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    squirrelmail · gpg plugin9 Tem 2007

  • CVE-2007-3778
    31İzleyin

    The G/PGP (GPG) Plugin 2.0, and 2.1dev before 20060912, for Squirrelmail allows remote attackers to execute arbitrary commands via shell met

    YüksekCVSS 7,5İstismar yokEPSS %3

    squirrelmail · gpg plugin15 Tem 2007

  • CVE-2005-0103
    31İzleyin

    PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by

    YüksekCVSS 7,5İstismar yokEPSS %2

    squirrelmail · squirrelmail24 Oca 2005

  • CVE-2007-2631
    30İzleyin

    Cross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actio

    YüksekCVSS 7,5İstismar yokEPSS %1

    squirrelmail · squirrelmail13 May 2007

  • CVE-2012-5623
    30İzleyin

    Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.

    YüksekCVSS 7,5İstismar yokEPSS %1

    squirrelmail · change passwd13 Şub 2020

  • CVE-2004-0520
    29İzleyin

    Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and scri

    OrtaCVSS 6,8Kavram kanıtıEPSS %7

    squirrelmail · squirrelmail18 Ağu 2004

  • CVE-2004-0639
    29İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or sc

    OrtaCVSS 6,8Kavram kanıtıEPSS %6

    squirrelmail · squirrelmail6 Ağu 2004

  • CVE-2006-4019
    28İzleyin

    Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary progr

    OrtaCVSS 6,4Kavram kanıtıEPSS %10

    squirrelmail · squirrelmail11 Ağu 2006

  • CVE-2007-6348
    28İzleyin

    SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse tha

    OrtaCVSS 6,8İstismar yokEPSS %4

    squirrelmail · squirrelmail14 Ara 2007