CVE-2008-2379

Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an e-mail message.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
squirrelmailsquirrelmail
𝑥
≤ 1.4.16
squirrelmailsquirrelmail
0.1
squirrelmailsquirrelmail
0.1.1
squirrelmailsquirrelmail
0.1.2
squirrelmailsquirrelmail
0.2
squirrelmailsquirrelmail
0.2.1
squirrelmailsquirrelmail
0.3
squirrelmailsquirrelmail
0.3.1
squirrelmailsquirrelmail
0.3pre1:pre1
squirrelmailsquirrelmail
0.3pre2:pre2
squirrelmailsquirrelmail
0.4
squirrelmailsquirrelmail
0.4pre1:pre1
squirrelmailsquirrelmail
0.4pre2:pre2
squirrelmailsquirrelmail
0.5
squirrelmailsquirrelmail
0.5pre1:pre1
squirrelmailsquirrelmail
0.5pre2:pre2
squirrelmailsquirrelmail
1.0
squirrelmailsquirrelmail
1.0.1
squirrelmailsquirrelmail
1.0.2
squirrelmailsquirrelmail
1.0.3
squirrelmailsquirrelmail
1.0.4
squirrelmailsquirrelmail
1.0.5
squirrelmailsquirrelmail
1.0.6
squirrelmailsquirrelmail
1.0pre1:pre1
squirrelmailsquirrelmail
1.0pre2:pre2
squirrelmailsquirrelmail
1.0pre3:pre3
squirrelmailsquirrelmail
1.1.0
squirrelmailsquirrelmail
1.1.1
squirrelmailsquirrelmail
1.1.2
squirrelmailsquirrelmail
1.1.3
squirrelmailsquirrelmail
1.2.0
squirrelmailsquirrelmail
1.2.0_rc3:_rc3
squirrelmailsquirrelmail
1.2.1
squirrelmailsquirrelmail
1.2.2
squirrelmailsquirrelmail
1.2.3
squirrelmailsquirrelmail
1.2.4
squirrelmailsquirrelmail
1.2.5
squirrelmailsquirrelmail
1.2.6
squirrelmailsquirrelmail
1.2.7
squirrelmailsquirrelmail
1.3.0
squirrelmailsquirrelmail
1.3.1
squirrelmailsquirrelmail
1.3.2
squirrelmailsquirrelmail
1.4.0
squirrelmailsquirrelmail
1.4.0_rc1:_rc1
squirrelmailsquirrelmail
1.4.0_rc2a:_rc2a
squirrelmailsquirrelmail
1.4.1
squirrelmailsquirrelmail
1.4.2
squirrelmailsquirrelmail
1.4.3
squirrelmailsquirrelmail
1.4.3_rc1:_rc1
squirrelmailsquirrelmail
1.4.3a:a
squirrelmailsquirrelmail
1.4.4
squirrelmailsquirrelmail
1.4.4_rc1:_rc1
squirrelmailsquirrelmail
1.4.5
squirrelmailsquirrelmail
1.4.5_rc1:_rc1
squirrelmailsquirrelmail
1.4.6
squirrelmailsquirrelmail
1.4.6_rc1:_rc1
squirrelmailsquirrelmail
1.4.7
squirrelmailsquirrelmail
1.4.8
squirrelmailsquirrelmail
1.4.9
squirrelmailsquirrelmail
1.4.9a:a
squirrelmailsquirrelmail
1.4.10
squirrelmailsquirrelmail
1.4.10a:a
squirrelmailsquirrelmail
1.4.11
squirrelmailsquirrelmail
1.4.12
squirrelmailsquirrelmail
1.4.15
squirrelmailsquirrelmail
1.4.15_rc1:_rc1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
squirrelmail
intrepid
Fixed 2:1.4.15-3ubuntu0.1
released
hardy
Fixed 2:1.4.13-2ubuntu1.1
released
gutsy
Fixed 2:1.4.10a-2ubuntu0.1
released
dapper
Fixed 2:1.4.6-1ubuntu0.2
released
References