Required CVE Record Information
Description
options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to modify or read the preferences of other users, conduct cross-site scripting XSS) attacks, and write arbitrary files.
References 13 Total
- novell.com: SUSE-SR:2005:018 vendor-advisory
- securityfocus.com: 14254 vdb-entry
- securityfocus.com: 20050714 [SM-ANNOUNCE] Patch available for CAN-2005-2095 mailing-list
- http://www.gulftech.org/?node=research&article_id=00090-07142005
- securityfocus.com: 20050714 SquirrelMail Arbitrary Variable Overwriting Vulnerability mailing-list
- bugzilla.redhat.com: FLSA:163047 vendor-advisory
- lists.apple.com: APPLE-SA-2005-08-15 vendor-advisory
- exchange.xforce.ibmcloud.com: squirrelmail-set-post-variable(21359) vdb-entry
- redhat.com: RHSA-2005:595 vendor-advisory
- debian.org: DSA-756 vendor-advisory
- lists.apple.com: APPLE-SA-2005-08-17 vendor-advisory
- http://www.squirrelmail.org/security/issue/2005-07-13
- oval.cisecurity.org: oval:org.mitre.oval:def:10500 vdb-entrysignature
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 13 Total
- novell.com: SUSE-SR:2005:018 vendor-advisoryx_transferred
- securityfocus.com: 14254 vdb-entryx_transferred
- securityfocus.com: 20050714 [SM-ANNOUNCE] Patch available for CAN-2005-2095 mailing-listx_transferred
- http://www.gulftech.org/?node=research&article_id=00090-07142005 x_transferred
- securityfocus.com: 20050714 SquirrelMail Arbitrary Variable Overwriting Vulnerability mailing-listx_transferred
- bugzilla.redhat.com: FLSA:163047 vendor-advisoryx_transferred
- lists.apple.com: APPLE-SA-2005-08-15 vendor-advisoryx_transferred
- exchange.xforce.ibmcloud.com: squirrelmail-set-post-variable(21359) vdb-entryx_transferred
- redhat.com: RHSA-2005:595 vendor-advisoryx_transferred
- debian.org: DSA-756 vendor-advisoryx_transferred
- lists.apple.com: APPLE-SA-2005-08-17 vendor-advisoryx_transferred
- http://www.squirrelmail.org/security/issue/2005-07-13 x_transferred
- oval.cisecurity.org: oval:org.mitre.oval:def:10500 vdb-entrysignaturex_transferred