Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to modify or read the preferences of other users, conduct cross-site scripting XSS) attacks, and write arbitrary files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SquirrelMail options_identities.php POST变量处理漏洞
Vulnerability Description
SquirrelMail是一套PHP4实现的个多功能Webmail程序。 SquirrelMail 1.4.4及之前版本中存在POST变量处理漏洞。 由于使用extract函数处理POST变量,使得攻击者可能利用此漏洞读取或修改其他用户的偏好设置、产生跨站脚本攻击或写入任意文件。
CVSS Information
N/A
Vulnerability Type
N/A