Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wj45-2qrw-hh28

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to modify or read the preferences of other users, conduct cross-site scripting XSS) attacks, and write arbitrary files.

options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to modify or read the preferences of other users, conduct cross-site scripting XSS) attacks, and write arbitrary files.

EPSS

Процентиль: 93%
0.09659
Низкий

Связанные уязвимости

ubuntu
около 20 лет назад

options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to modify or read the preferences of other users, conduct cross-site scripting XSS) attacks, and write arbitrary files.

redhat
около 20 лет назад

options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to modify or read the preferences of other users, conduct cross-site scripting XSS) attacks, and write arbitrary files.

nvd
около 20 лет назад

options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to modify or read the preferences of other users, conduct cross-site scripting XSS) attacks, and write arbitrary files.

debian
около 20 лет назад

options_identities.php in SquirrelMail 1.4.4 and earlier uses the extr ...

EPSS

Процентиль: 93%
0.09659
Низкий