>> SquirrelMail Address Add Plugin "first" Cross Site Scripting Vulnerability
Title : SquirrelMail Address Add Plugin "first" Cross Site Scripting Vulnerability VUPEN ID : VUPEN/ADV-2005-1887 CVE ID : CVE-2005-3128 CWE ID : CWE-
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-09-29
Technical Description
A vulnerability has been identified in SquirrelMail Address Add Plugin, which may be exploited by attackers to inject malicious HTML code. This flaw is due to an input validation error in "add.php when processing a specially crafted "first" parameter, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser.