SquirrelMail是一个用php4写的功能丰富的webmail程序。可以运行于Linux/Unix系统。 在某些SquirrelMail版本中,如果HTML格式的邮件中包含恶意内容的代码,如插入JavaScript脚本,可以导致脚本代码被执行。也可能包含其他相关SquirrelMail脚本的引用,可能导致以认证用户的身份进行恶意行为操作。 脚本compose.php在受影响用户发新邮件时存在此安全漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2002-1647 | Slash Slashcode密码泄露漏洞 | |
| CVE-2005-0469 | 多个Telnet客户端slc_add_reply() 缓冲区溢出漏洞 | |
| CVE-2005-0468 | Telnet客户端env_opt_add() 缓冲区溢出漏洞 | |
| CVE-2004-1773 | GNU Sharutils多个缓冲区溢出漏洞 | |
| CVE-2004-1772 | GNU Sharutils shar命令行解析缓冲区溢出漏洞 | |
| CVE-2002-1656 | X-News不安全用户数据库权限漏洞 | |
| CVE-2002-1655 | Netscape Enterprise Server Web Publisher拒绝服务攻击漏洞 | |
| CVE-2002-1654 | Netscape企业Web服务器蛮力授权攻击漏洞 | |
| CVE-2002-1653 | Cryptcat加密连接弱点 | |
| CVE-2002-1652 | CGIEmail远程缓冲区溢出漏洞 | |
| CVE-2002-1651 | Verity Search97错误页面跨站脚本漏洞 | |
| CVE-2002-1650 | SquirrelMail拼写检查器漏洞 | |
| CVE-2002-1649 | SquirrelMail对恶意HTML格式邮件处理的漏洞 | |
| CVE-2002-1634 | Netware下的Netscape Enterprise Web服务器信息泄露漏洞 | |
| CVE-2002-1646 | SSH Communications SSH AllowedAuthentications配置存在漏洞 | |
| CVE-2002-1645 | SSH Communications Secure Shell Windows客户端URLCatcher缓冲区溢出漏洞 | |
| CVE-2002-1644 | SSH Communications SSH Server权限提升漏洞 | |
| CVE-2002-1643 | Real Networks Helix Universal Server RTSP transport字段远程缓冲区溢出漏洞 | |
| CVE-2002-1642 | PostgreSQL VACUUM命令数据丢失漏洞 | |
| CVE-2002-1641 | Oracle Web Cache远程缓冲区溢出漏洞 |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet