Логотип exploitDog
bind:"CVE-2009-1579" OR bind:"CVE-2009-1578" OR bind:"CVE-2009-1581"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2009-1579" OR bind:"CVE-2009-1578" OR bind:"CVE-2009-1581"

Количество 16

Количество 16

oracle-oval логотип

ELSA-2009-1066

около 16 лет назад

ELSA-2009-1066: squirrelmail security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2009-1579

около 16 лет назад

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2009-1579

около 16 лет назад

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-1579

около 16 лет назад

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2009-1579

около 16 лет назад

The map_yp_alias function in functions/imap_general.php in SquirrelMai ...

CVSS2: 6.8
EPSS: Низкий
github логотип

GHSA-gff5-24h3-hxcw

около 3 лет назад

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.

EPSS: Низкий
ubuntu логотип

CVE-2009-1581

около 16 лет назад

functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2009-1581

около 16 лет назад

functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-1581

около 16 лет назад

functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2009-1581

около 16 лет назад

functions/mime.php in SquirrelMail before 1.4.18 does not protect the ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2009-1578

около 16 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2009-1578

около 16 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-1578

около 16 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2009-1578

около 16 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail be ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-x532-p2m7-cf32

около 3 лет назад

functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message.

EPSS: Низкий
github логотип

GHSA-2ffv-f223-6p7w

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2009-1066

ELSA-2009-1066: squirrelmail security update (IMPORTANT)

около 16 лет назад
ubuntu логотип
CVE-2009-1579

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.

CVSS2: 6.8
5%
Низкий
около 16 лет назад
redhat логотип
CVE-2009-1579

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.

CVSS2: 7.5
5%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-1579

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.

CVSS2: 6.8
5%
Низкий
около 16 лет назад
debian логотип
CVE-2009-1579

The map_yp_alias function in functions/imap_general.php in SquirrelMai ...

CVSS2: 6.8
5%
Низкий
около 16 лет назад
github логотип
GHSA-gff5-24h3-hxcw

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.

5%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2009-1581

functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message.

CVSS2: 4.3
1%
Низкий
около 16 лет назад
redhat логотип
CVE-2009-1581

functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message.

CVSS2: 4.3
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-1581

functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message.

CVSS2: 4.3
1%
Низкий
около 16 лет назад
debian логотип
CVE-2009-1581

functions/mime.php in SquirrelMail before 1.4.18 does not protect the ...

CVSS2: 4.3
1%
Низкий
около 16 лет назад
ubuntu логотип
CVE-2009-1578

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).

CVSS2: 4.3
3%
Низкий
около 16 лет назад
redhat логотип
CVE-2009-1578

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).

CVSS2: 4.3
3%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-1578

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).

CVSS2: 4.3
3%
Низкий
около 16 лет назад
debian логотип
CVE-2009-1578

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail be ...

CVSS2: 4.3
3%
Низкий
около 16 лет назад
github логотип
GHSA-x532-p2m7-cf32

functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message.

1%
Низкий
около 3 лет назад
github логотип
GHSA-2ffv-f223-6p7w

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).

3%
Низкий
около 3 лет назад

Уязвимостей на страницу