Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
SquirrelMail 1.4.8 released - fixes variable overwriting attack Aug 11 2006 12:26PM
Thijs Kinkhorst (kink squirrelmail org)
Hello all,

Today SquirrelMail version 1.4.8 has been released with a collection of
bugfixes and an important security fix. It was possible for an
authenticated user to overwrite random variables in the compose.php
script. This may open up possible attack vectors like reading or
overwriting a user's...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus