CVE-2009-1578
Published May 14, 2009
Last updated 7 years ago
Overview
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B2FF0DF6-AEEC-4099-B1C4-19EDC1FDD564" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B23AEC37-88CE-488D-B9D2-2B0322D0FC8A", "versionEndIncluding": "1.4.17" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C2F0267-47D5-436F-B9F6-505CEC582AD3" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:0.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "565E131D-56A9-46AB-800D-12B097FE3B7B" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:0.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4FAB6F43-2DAE-4E02-8F0A-EE4D4FB3E005" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86DB6243-3A4A-419E-B6C5-D61F5B0A1E7F" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:0.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A2805F37-B8E6-4647-9E90-50763C7E4952" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "284E543F-6AC3-45CD-8448-3A1D4D3DD469" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:0.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6C7E957E-81C0-4FA3-9944-5E514874BED8" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:0.3pre1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8FF0DACB-F875-448B-86DF-D40531A2A762" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:0.3pre2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "651432C3-1EE9-4BBA-A1CF-DCC9F19954D5" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E11C84D0-13B5-4298-B9F3-BF5C6F927793" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:0.4pre1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DEE72FA1-E635-436B-A650-A8D4040925B0" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:0.4pre2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "512F2AB5-EB24-4846-B924-377D040C131A" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "25F42A76-BF06-4DA9-8667-0E81D17B5B9C" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:0.5pre1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "02410BAB-C1D7-4883-A27B-C13A72707CE0" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:0.5pre2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8509AAEE-225C-4907-884D-F9796ACA40F7" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DD41781D-1F7E-43A7-AD59-ADFE1D04D825" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "78650B7E-9638-46FF-9656-38E8DFE3FA93" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "94CBBB8E-E0AB-4F7B-A55E-F7BD5F83EAAB" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4C1E1172-9D9E-439E-BD4B-4EF372344F59" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "67E9817E-FF56-4FD0-B6C7-F4EEB25AD0CF" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5EBF40C5-6272-427C-97A1-3CE3B1D47B12" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DB15C5DD-2D76-47ED-883C-D1901B96F391" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.0pre1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E3E249ED-76DA-44B3-A3A7-788F4B1A19DD" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.0pre2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ABD0A21F-CD80-4B01-B5D3-9B2281E4F143" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.0pre3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BA516843-2A45-4705-9669-4B719F722192" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6DA068C0-8067-4A94-9F74-0D1DACF9A9EC" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "49F37AD5-120E-4FEA-ADA5-F6C3434B9BA6" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C059835E-8FD9-40DF-BA6F-7E313E49F511" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5E28A825-56F4-4EC5-9D62-661C0F4B477F" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "545CD944-7C64-49E3-A32E-3388B5F3ECF1" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A55A98B3-34ED-4A90-BB78-50CB56B1B51F" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.0_rc3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F22E1FA6-7C9C-4D01-A645-CF41939C1988" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CC5143ED-D4C5-4830-9C96-0B54D03679CB" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B765AEC-09E9-456C-8B57-09927E55D119" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0AAFC3B0-DCE3-4190-B279-E095C666FA34" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9291A565-0BD6-4B5E-B45F-9DE65AB8159D" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B6F53A84-FC66-4963-A728-7285F63D4761" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "69A941FF-423E-49C5-AE1F-FE7ED016CA3D" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B34FDB1D-881B-4343-A76E-F23B93A0469A" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E4DCB20-2A7F-4EE4-BAFA-AD74CD4456AB" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "052914F8-B52C-4AB4-8F85-68D788B588C9" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "617C554F-8E7D-4F8A-AF63-C193934C8215" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "15F11950-A2E4-4F57-BF87-57788B841A21" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8F886B99-E996-4BF7-9BE3-14A6713A997F" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "65801122-2E5D-4244-9D37-5483F5C731F2" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5A29559D-0DB8-40C8-A6E6-4F37DDD27571" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "026730B8-3919-4100-8607-C640ADBDD662" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C179A3C-8C8C-429B-BACA-8ADAE4170465" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4.0_rc1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C8F869F3-6D8D-4C95-95F7-5AE42C67362B" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4.0_rc2a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3B96BB4F-12B0-460A-B5CC-8BA6D69911FD" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4AD31177-05BB-4623-AED7-765DB7E44E47" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "18AF3BC6-E33B-44BD-A2F6-A7F5244AA4FE" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4.10a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "77776503-3258-400D-8404-233EAFA940AB" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "682BC5E2-F2C5-4B6F-8EF0-E05152BB9B12" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ABC24558-B7C1-4DE7-BC24-AF092DF0DE97" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0986D113-C9F9-4645-8968-D165EC6B917D" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4.15_rc1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B85F80F3-DC0E-4228-9FA3-D870BC2200D2" }, { "criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B8608AE1-7930-47CF-B2E8-9E86E2FB5A20" } ], "operator": "OR" } ] } ]