Donations
News
About
Support
Security
Screen shots
Download
Plugins
Documentation
Sponsors
Bounties

search site:

[フレーム]


Junk Email Filter






Security Notice
Phishing campain
Version 1.4.15
Security Upgrade

Security

NOTE: If you're looking to contact us regarding spam supposedly sent by SquirrelMail, please read this explanation of why we are not related to this scam.

If you want to contact us regarding your lost password, not being able to login or other problems with your mail account, please go our end user information.


The SquirrelMail Project takes security very seriously. If you think you've discovered a security-related issue in SquirrelMail, please contact us directly at security-2021 <at> squirrelmail.org. We will do our best to work with you towards a solution as quickly as possible and will of course give all credit where it's due.

Below you will find a list with known issues in past SquirrelMail versions. A legend of the columns is below the table.

DateIssueVersions AffectedRGCVE IDs
2025年04月02日 XSS vulnerability <= 1.4.23-svn-20250401
<= 1.5.2-svn-20250401
0 CVE-2025-30090
2021年10月15日 INVALID: Insecure use of unserialize() with untrusted input None 0 CVE-2020-14933
2019年07月01日 XSS vulnerability in message display <= 1.4.22 0 CVE-2019-12970
2019年02月26日 Multiple XSS vulnerabilities <= 1.4.22 0 CVE-2018-14950, CVE-2018-14951, CVE-2018-14952, CVE-2018-14953, CVE-2018-14954, CVE-2018-14955
2018年04月04日 Attachments directory traversal vulnerability <= 1.4.22 0 CVE-2018-8741
2017年04月24日 Arbitrary code execution <= 1.4.22 0 CVE-2017-7692
2012年03月09日 Cross-site scripting vulnerability in the Autocomplete plugin < 3.0 0 CVE-2012-0323
2011年07月12日 Clickjacking <= 1.4.21 0 CVE-2010-4554
2011年07月11日 Multiple XSS vulnerabilities <= 1.4.21 0 CVE-2010-4555, CVE-2011-2752, CVE-2011-2753
2011年07月10日 XSS vulnerability in message display <= 1.4.21 0 CVE-2011-2023
2010年07月23日 DoS risk against login page <= 1.4.20 0 CVE-2010-2813
2010年06月21日 Mail Fetch plugin as network scanner <= 1.4.20 0 CVE-2010-1637
2009年08月12日 CSRF in all forms <= 1.4.19 0 SA34627
2009年05月12日 CSS positioning vulnerability <= 1.4.17 0 CVE-2009-1581
2009年05月11日 Session fixation vulnerability <= 1.4.17 0 CVE-2009-1580
2009年05月10日 Server-side code injection in map_yp_alias username map <= 1.4.18 0 CVE-2009-1579, CVE-2009-1381
2009年05月09日 Cross site scripting issues in decrypt_headers.php <= 1.4.17 0 CVE-2009-1578
2009年05月08日 Multiple cross site scripting issues <= 1.4.17 0 CVE-2009-1578
2008年12月04日 Cross site scripting in HTML filter 1.4.0 - 1.4.16 0 CVE-2008-2379
2008年09月28日 Cookies for SSL connection could be sent over non-SSL 1.4.0 - 1.4.15 0 CVE-2008-3663
2007年12月13日 1.4.12 and 1.4.11 Package Compromise 1.4.11&12 0 CVE-2007-6348
2007年05月09日 Cross site scripting in HTML filter 1.4.0-1.4.9a 0 CVE-2007-1262, CVE-2007-2589
2006年12月03日 Workaround for Internet Explorer MIME handling IE 0
2006年12月02日 Cross site scripting in compose, draft & HTML mail viewing 1.4.0 - 1.4.9 0 CVE-2006-6142
2006年08月11日 Variable overwriting in compose.php 1.4.0 - 1.4.7 0 CVE-2006-4019
2006年06月22日 Disputed: search.php cross site scripting none 1 CVE-2006-3174
2006年06月01日 Local file inclusion <= 1.4.6 1 CVE-2006-2842
2006年02月15日 IMAP injection in sqimap_mailbox_select mailbox parameter <= 1.4.5 0 CVE-2006-0377
2006年02月10日 Possible XSS in MagicHTML (IE only) <= 1.4.5 0 CVE-2006-0195
2006年02月01日 Possible XSS through right_frame parameter in webmail.php <= 1.4.5 0 CVE-2006-0188
2005年07月13日 $_POST variable handling in options_identites allows for different attacks <= 1.4.5-RC1 1 CVE-2005-2095
2005年06月15日 Several cross site scripting vulnerabilities <= 1.4.4 0 CVE-2005-1769
2005年01月20日 XSS vulnerability in webmail.php <= 1.4.4-RC1 0 CVE-2005-0104
2005年01月19日 Frame content changing in webmail.php <= 1.4.4-RC1 0 CVE-2005-0103
2005年01月14日 Local file inclusions in prefs.php 1.4.3-RC1 - 1.4.4-RC1 1 CVE-2005-0075
2004年11月10日 XSS vulnerability in decodeHeader() <= 1.4.3a 0 CVE-2004-1036
2004年05月30日 XSS vulnerability in Content-Type display in read_body <= 1.4.3-RC1 0
2004年05月10日 SQL injection vulnerability in addressbook <= 1.4.2 0 CVE-2004-0521
2004年05月01日 Multiple XSS vulnerabilities <= 1.4.2 0 CVE-2004-0519, CVE-2004-0520
2004年04月03日 XSS vulnerability in incoming email headers <= 1.4.0-RC2a 0
2004年04月01日 XSS vulnerability when replying to malicious sources <= 1.4.0-RC2a 0

The column RG indicates whether the vulnerability only applies to systems that have the PHP register_globals setting turned On, something that is highly discouraged by both PHP and the SquirrelMail team.

CVE IDs are used for cross-referencing security issues between distributions.

This page only lists known issues since the start of the 1.4.0 Stable series.


Website Bug Reports

We'd like to express much gratitude to reporters of bugs with our website as follows:

  • Murat Yılmazlar - https://tr.linkedin.com/in/muratyilmazlarr
  • Balaji P R - https://www.linkedin.com/in/balagpy
  • Stef
  • Ashish Pathak - https://twitter.com/pathakbackz
  • דביר לוי
  • Thomas Chauchefoin
© 1999-2016 by The SquirrelMail Project Team

AltStyle によって変換されたページ (->オリジナル) /