FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0519

This CVE name corresponds to:

Entered Topic
2004-07-05 "Content-Type" XSS vulnerability affecting other webmail systems

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0519
Phase Assigned(20040602)

Description

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.

References

Source Reference
BUGTRAQ 20040429 SquirrelMail Cross Scripting Attacks....
BUGTRAQ 20040430 Re: SquirrelMail Cross Scripting Attacks....
CONECTIVA CLA-2004:858
DEBIAN DSA-535
FEDORA FEDORA-2004-160
FEDORA FEDORA-2004-1733
GENTOO GLSA-200405-16
REDHAT RHSA-2004:240
SGI 20040604-01-U
SUSE SUSE-SR:2005:019
BID 10246
OVAL oval:org.mitre.oval:def:1006
OVAL oval:org.mitre.oval:def:10274
SECUNIA 11531
SECUNIA 11686
SECUNIA 11870
SECUNIA 12289
XF squirrel-composephp-xss(16025)