Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via an IMG URL with modified send_to and subject parameters.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2002-01/0310.html | Exploit |
http://www.kb.cert.org/vuls/id/153043 | US Government Resource |
http://www.securityfocus.com/bid/3956 | Patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7989 |
Configurations
Information
Published : 2002-12-30 21:00
Updated : 2017-07-10 18:29
NVD link : CVE-2002-1648
Mitre link : CVE-2002-1648
JSON object : View
CWE
Products Affected
squirrelmail
- squirrelmail