Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3jq4-6p6j-xq72

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SquirrelMail 1.4.6 and earlier, with register_globals enabled, allows remote attackers to hijack cookies in src/redirect.php via unknown vectors. NOTE: while "cookie theft" is frequently associated with XSS, the vendor disclosure is too vague to be certain of this.

SquirrelMail 1.4.6 and earlier, with register_globals enabled, allows remote attackers to hijack cookies in src/redirect.php via unknown vectors. NOTE: while "cookie theft" is frequently associated with XSS, the vendor disclosure is too vague to be certain of this.

EPSS

Процентиль: 60%
0.00392
Низкий

Связанные уязвимости

ubuntu
около 19 лет назад

SquirrelMail 1.4.6 and earlier, with register_globals enabled, allows remote attackers to hijack cookies in src/redirect.php via unknown vectors. NOTE: while "cookie theft" is frequently associated with XSS, the vendor disclosure is too vague to be certain of this.

nvd
около 19 лет назад

SquirrelMail 1.4.6 and earlier, with register_globals enabled, allows remote attackers to hijack cookies in src/redirect.php via unknown vectors. NOTE: while "cookie theft" is frequently associated with XSS, the vendor disclosure is too vague to be certain of this.

debian
около 19 лет назад

SquirrelMail 1.4.6 and earlier, with register_globals enabled, allows ...

EPSS

Процентиль: 60%
0.00392
Низкий