// For flags

CVE-2007-1262

XSS through HTML message in squirrelmail

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple cross-site scripting (XSS) vulnerabilities in the HTML filter in SquirrelMail 1.4.0 through 1.4.9a allow remote attackers to inject arbitrary web script or HTML via the (1) data: URI in an HTML e-mail attachment or (2) various non-ASCII character sets that are not properly filtered when viewed with Microsoft Internet Explorer.

Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en el filtro de HTML en el SquirrelMail 1.4.0 hasta la 1.4.9a permiten a atacantes remotos la inyección de secuencias de comandos web o HTML de su elección mediante (1) datos: un URI en un adjunto de un correo electrónico en HTML o (2) mediante varios juegos de caracteres no-ASCII que no son filtrados adecuadamente cuando son visualizados por el Microsoft Internet Explorer.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-03-03 CVE Reserved
  • 2007-05-11 CVE Published
  • 2024-07-06 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (26)
URL Date SRC
URL Date SRC
http://secunia.com/advisories/25200 2017-10-11
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.0
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.0"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.1
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.1"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.2
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.2"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.3
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.3"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.3_r3
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.3_r3"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.3_rc1
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.3_rc1"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.3a
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.3a"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.3aa
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.3aa"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.4
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.4"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.4_rc1
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.4_rc1"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.5
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.5"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.6
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.6"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.6_cvs
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.6_cvs"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.6_rc1
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.6_rc1"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.7
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.7"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.8
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.8"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.9
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.9"
-
Affected
Squirrelmail
Search vendor "Squirrelmail"
Squirrelmail
Search vendor "Squirrelmail" for product "Squirrelmail"
1.4.9a
Search vendor "Squirrelmail" for product "Squirrelmail" and version "1.4.9a"
-
Affected