Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian DSA 535-1 Critical: SquirrelMail XSS And SQL Injection Risks

debian
Calendar Grey August 11, 2004
Debian Logo
Ubuntu has issued a crucial security update to address vulnerabilities in Roundcube, focusing on CSRF and Command injection risks. Users should update quickly to protect their data
This patch addresses multiple Cross Site Scripting and SQL Injection vulnerabilities.

Summary

Four vulnerabilities were discovered in squirrelmail:

CAN-2004-0519 - Multiple cross-site scripting (XSS) vulnerabilities
in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary
script as other users and possibly steal authentication information
via multiple attack vectors, including the mailbox parameter in
compose.php.

CAN-2004-0520 - Cross-site scripting (XSS) vulnerability in mime.php
for SquirrelMail before 1.4.3 allows remote attackers to insert
arbitrary HTML and script via the content-type mail header, as
demonstrated using read_body.php.

CAN-2004-0521 - SQL injection vulnerability in SquirrelMail before
1.4.3 RC1 allows remote attackers to execute unauthorized SQL
statements, with unknown impact, probably via abook_database.php.

CAN-2004-0639 - Multiple cross-site scripting (XSS) vulnerabilities
in Squirrelmail 1.2.10 and earlier allow remote attackers to inject
arbitrary HTML or script via (1) the $mailer variable in
read_body.php, (2) the $senderNames_part varia...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: squirrelmail

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here