Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2002-1648

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SquirrelMail是一个用php4写的功能丰富的webmail程序。可以运行于Linux/Unix系统。 在某些SquirrelMail版本中,如果HTML格式的邮件中包含恶意内容的代码,如插入JavaScript脚本,可以导致脚本代码被执行。也可能包含其他相关SquirrelMail脚本的引用,可能导致以认证用户的身份进行恶意行为操作。 脚本compose.php在受影响用户发新邮件时存在此安全漏洞。

AI Predicted 6.5 Difficulty: Trivial EPSS 3.44% · P88
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2002-1648

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via an IMG URL with modified send_to and subject parameters.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
SquirrelMail对恶意HTML格式邮件处理的漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SquirrelMail是一个用php4写的功能丰富的webmail程序。可以运行于Linux/Unix系统。 在某些SquirrelMail版本中,如果HTML格式的邮件中包含恶意内容的代码,如插入JavaScript脚本,可以导致脚本代码被执行。也可能包含其他相关SquirrelMail脚本的引用,可能导致以认证用户的身份进行恶意行为操作。 脚本compose.php在受影响用户发新邮件时存在此安全漏洞。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2002-1648

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2002-1648

登录查看更多情报信息。

Vendor Advisories for CVE-2002-1648 (3)

Mailing List Discussions for CVE-2002-1648 (1)

Same Patch Batch · n/a · 2005-03-28 · 26 CVEs total

CVE-2002-1647 Slash Slashcode密码泄露漏洞
CVE-2005-0469 多个Telnet客户端slc_add_reply() 缓冲区溢出漏洞
CVE-2005-0468 Telnet客户端env_opt_add() 缓冲区溢出漏洞
CVE-2004-1773 GNU Sharutils多个缓冲区溢出漏洞
CVE-2004-1772 GNU Sharutils shar命令行解析缓冲区溢出漏洞
CVE-2002-1656 X-News不安全用户数据库权限漏洞
CVE-2002-1655 Netscape Enterprise Server Web Publisher拒绝服务攻击漏洞
CVE-2002-1654 Netscape企业Web服务器蛮力授权攻击漏洞
CVE-2002-1653 Cryptcat加密连接弱点
CVE-2002-1652 CGIEmail远程缓冲区溢出漏洞
CVE-2002-1651 Verity Search97错误页面跨站脚本漏洞
CVE-2002-1650 SquirrelMail拼写检查器漏洞
CVE-2002-1649 SquirrelMail对恶意HTML格式邮件处理的漏洞
CVE-2002-1634 Netware下的Netscape Enterprise Web服务器信息泄露漏洞
CVE-2002-1646 SSH Communications SSH AllowedAuthentications配置存在漏洞
CVE-2002-1645 SSH Communications Secure Shell Windows客户端URLCatcher缓冲区溢出漏洞
CVE-2002-1644 SSH Communications SSH Server权限提升漏洞
CVE-2002-1643 Real Networks Helix Universal Server RTSP transport字段远程缓冲区溢出漏洞
CVE-2002-1642 PostgreSQL VACUUM命令数据丢失漏洞
CVE-2002-1641 Oracle Web Cache远程缓冲区溢出漏洞

Showing top 20 of 26 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2002-1648

No comments yet


Leave a comment