Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
SquirrelMail Cross Scripting Attacks.... Apr 29 2004 09:09PM
Alvin Alex (alvin_gboy hotmail com)


SquirrelMail latest version (although is tested on version 1.4.2) is prone to many cross scripting attacks that can be used to steal user cookies.The Exploit lies in the way squirrel mail represents the folder names and shows them.To make the matters worse.No extra unique variable added to the url...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus