CVE-2007-1262
CVE-2007-1262
Multiple cross-site scripting (XSS) vulnerabilities in the HTML filter in SquirrelMail 1.4.0 through 1.4.9a allow remote attackers to inject arbitrary web script or HTML via the (1) data: URI in an HTML e-mail attachment or (2) various non-ASCII character sets that are not properly filtered when viewed with Microsoft Internet Explorer.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://docs.info.apple.com/article.html?artnum=306172http://jvndb.jvn.jp/ja/contents/2007/JVNDB-2007-000398.htmlhttp://jvn.jp/en/jp/JVN09157962/index.htmlhttp://lists.apple.com/archives/security-announce//2007/Jul/msg00004.htmlhttp://osvdb.org/35887http://osvdb.org/35888http://secunia.com/advisories/25200http://secunia.com/advisories/25236http://secunia.com/advisories/25320http://secunia.com/advisories/25690http://secunia.com/advisories/25787http://secunia.com/advisories/26235