>> SquirrelMail Multiple Cross Site Scripting Vulnerabilities
Title : SquirrelMail Multiple Cross Site Scripting Vulnerabilities VUPEN ID : VUPEN/ADV-2005-0800 CVE ID : CVE-2005-1769 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-06-16
Technical Description
Multiple vulnerabilities were identified in SquirrelMail, which may be exploited by malicious users to conduct cross site scripting attacks. These flaws are due to input validation errors when handling specially crafted parameters, which could be exploited to cause arbitrary scripting code to be executed by the user's browser via either URL manipulation or by sending a specially crafted email to a victim.