Back to search
CVE-2008-2379
Published: Dec 5, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an e-mail message.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
oval:org.mitre.oval:def:9764
vdb-entry
signature
x_refsource_OVAL
33937
third-party-advisory
x_refsource_SECUNIA
33071
third-party-advisory
x_refsource_SECUNIA
FEDORA-2008-10918
vendor-advisory
x_refsource_FEDORA
33054
third-party-advisory
x_refsource_SECUNIA
http://support.apple.com/kb/HT3438
x_refsource_CONFIRM
APPLE-SA-2009-02-12
vendor-advisory
x_refsource_APPLE
ADV-2008-3332
vdb-entry
x_refsource_VUPEN
DSA-1682
vendor-advisory
x_refsource_DEBIAN
SUSE-SR:2008:027
vendor-advisory
x_refsource_SUSE
32603
vdb-entry
x_refsource_BID
32143
third-party-advisory
x_refsource_SECUNIA
squirrelmail-html-xss(47024)
vdb-entry
x_refsource_XF
http://security-net.biz/wsw/index.php?p=254&n=190
x_refsource_MISC
FEDORA-2008-10740
vendor-advisory
x_refsource_FEDORA
http://www.squirrelmail.org/index.php
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now