Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) drop-down selection lists, (2) the > (greater than) character in the SquirrelSpell spellchecking plugin, and (3) errors associated with the Index Order (aka options_order) page.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SquirrelMail多个跨站脚本攻击漏洞
Vulnerability Description
SquirrelMail是一套跨平台的使用PHP4开发Webmail邮件系统。 SquirrelMail 1.4.21及之前版本中存在多个跨站脚本攻击漏洞。由于向SquirrelSpell spellchecking功能和索引命令页传递的某些输入在返回给用户之前没有经过正确过滤,远程攻击者可利用该漏洞执行受影响站点上下文的用户浏览器会话中的任意HTML和脚本代码。
CVSS Information
N/A
Vulnerability Type
N/A