4.3

CVE-2008-2379

Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an e-mail message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SquirrelmailSquirrelmail Version <= 1.4.16
SquirrelmailSquirrelmail Version0.1
SquirrelmailSquirrelmail Version0.1.1
SquirrelmailSquirrelmail Version0.1.2
SquirrelmailSquirrelmail Version0.2
SquirrelmailSquirrelmail Version0.2.1
SquirrelmailSquirrelmail Version0.3
SquirrelmailSquirrelmail Version0.3.1
SquirrelmailSquirrelmail Version0.3pre1
SquirrelmailSquirrelmail Version0.3pre2
SquirrelmailSquirrelmail Version0.4
SquirrelmailSquirrelmail Version0.4pre1
SquirrelmailSquirrelmail Version0.4pre2
SquirrelmailSquirrelmail Version0.5
SquirrelmailSquirrelmail Version0.5pre1
SquirrelmailSquirrelmail Version0.5pre2
SquirrelmailSquirrelmail Version1.0
SquirrelmailSquirrelmail Version1.0.1
SquirrelmailSquirrelmail Version1.0.2
SquirrelmailSquirrelmail Version1.0.3
SquirrelmailSquirrelmail Version1.0.4
SquirrelmailSquirrelmail Version1.0.5
SquirrelmailSquirrelmail Version1.0.6
SquirrelmailSquirrelmail Version1.0pre1
SquirrelmailSquirrelmail Version1.0pre2
SquirrelmailSquirrelmail Version1.0pre3
SquirrelmailSquirrelmail Version1.1.0
SquirrelmailSquirrelmail Version1.1.1
SquirrelmailSquirrelmail Version1.1.2
SquirrelmailSquirrelmail Version1.1.3
SquirrelmailSquirrelmail Version1.2.0
SquirrelmailSquirrelmail Version1.2.0_rc3
SquirrelmailSquirrelmail Version1.2.1
SquirrelmailSquirrelmail Version1.2.2
SquirrelmailSquirrelmail Version1.2.3
SquirrelmailSquirrelmail Version1.2.4
SquirrelmailSquirrelmail Version1.2.5
SquirrelmailSquirrelmail Version1.2.6
SquirrelmailSquirrelmail Version1.2.7
SquirrelmailSquirrelmail Version1.3.0
SquirrelmailSquirrelmail Version1.3.1
SquirrelmailSquirrelmail Version1.3.2
SquirrelmailSquirrelmail Version1.4.0
SquirrelmailSquirrelmail Version1.4.0_rc1
SquirrelmailSquirrelmail Version1.4.0_rc2a
SquirrelmailSquirrelmail Version1.4.1
SquirrelmailSquirrelmail Version1.4.2
SquirrelmailSquirrelmail Version1.4.3
SquirrelmailSquirrelmail Version1.4.3_rc1
SquirrelmailSquirrelmail Version1.4.3a
SquirrelmailSquirrelmail Version1.4.4
SquirrelmailSquirrelmail Version1.4.4_rc1
SquirrelmailSquirrelmail Version1.4.5
SquirrelmailSquirrelmail Version1.4.5_rc1
SquirrelmailSquirrelmail Version1.4.6
SquirrelmailSquirrelmail Version1.4.6_rc1
SquirrelmailSquirrelmail Version1.4.7
SquirrelmailSquirrelmail Version1.4.8
SquirrelmailSquirrelmail Version1.4.9
SquirrelmailSquirrelmail Version1.4.9a
SquirrelmailSquirrelmail Version1.4.10
SquirrelmailSquirrelmail Version1.4.10a
SquirrelmailSquirrelmail Version1.4.11
SquirrelmailSquirrelmail Version1.4.12
SquirrelmailSquirrelmail Version1.4.15
SquirrelmailSquirrelmail Version1.4.15_rc1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.32% 0.794
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.