Donations
News
About
Support
Security
Screen shots
Download
Plugins
Documentation
Sponsors
Bounties
search site:
[フレーム]
Junk Email Filter
|
Security
NOTE: If you're looking to contact us regarding spam
supposedly sent by SquirrelMail, please read
this explanation of why we
are not related to this scam.
If you want to contact us regarding your lost password,
not being able to login or other problems with your
mail account, please go our end user
information.
The SquirrelMail Project takes security very seriously. If you think
you've discovered a security-related issue in SquirrelMail, please contact
us directly at security-2021 <at> squirrelmail.org.
We will do our best to work with you towards a solution as quickly as possible
and will of course give all credit where it's due.
Below you will find a list with known issues in past SquirrelMail versions.
A legend of the columns is below the table.
| Date | Issue | Versions Affected | RG | CVE IDs |
| 2025年04月02日 |
XSS vulnerability |
<= 1.4.23-svn-20250401 <= 1.5.2-svn-20250401 |
0 |
CVE-2025-30090 |
| 2021年10月15日 |
INVALID: Insecure use of unserialize() with untrusted input |
None |
0 |
CVE-2020-14933 |
| 2019年07月01日 |
XSS vulnerability in message display |
<= 1.4.22 |
0 |
CVE-2019-12970 |
| 2019年02月26日 |
Multiple XSS vulnerabilities |
<= 1.4.22 |
0 |
CVE-2018-14950, CVE-2018-14951, CVE-2018-14952, CVE-2018-14953, CVE-2018-14954, CVE-2018-14955 |
| 2018年04月04日 |
Attachments directory traversal vulnerability |
<= 1.4.22 |
0 |
CVE-2018-8741 |
| 2017年04月24日 |
Arbitrary code execution |
<= 1.4.22 |
0 |
CVE-2017-7692 |
| 2012年03月09日 |
Cross-site scripting vulnerability in the Autocomplete plugin |
< 3.0 |
0 |
CVE-2012-0323 |
| 2011年07月12日 |
Clickjacking |
<= 1.4.21 |
0 |
CVE-2010-4554 |
| 2011年07月11日 |
Multiple XSS vulnerabilities |
<= 1.4.21 |
0 |
CVE-2010-4555, CVE-2011-2752, CVE-2011-2753 |
| 2011年07月10日 |
XSS vulnerability in message display |
<= 1.4.21 |
0 |
CVE-2011-2023 |
| 2010年07月23日 |
DoS risk against login page |
<= 1.4.20 |
0 |
CVE-2010-2813 |
| 2010年06月21日 |
Mail Fetch plugin as network scanner |
<= 1.4.20 |
0 |
CVE-2010-1637 |
| 2009年08月12日 |
CSRF in all forms |
<= 1.4.19 |
0 |
SA34627 |
| 2009年05月12日 |
CSS positioning vulnerability |
<= 1.4.17 |
0 |
CVE-2009-1581 |
| 2009年05月11日 |
Session fixation vulnerability |
<= 1.4.17 |
0 |
CVE-2009-1580 |
| 2009年05月10日 |
Server-side code injection in map_yp_alias username map |
<= 1.4.18 |
0 |
CVE-2009-1579, CVE-2009-1381 |
| 2009年05月09日 |
Cross site scripting issues in decrypt_headers.php |
<= 1.4.17 |
0 |
CVE-2009-1578 |
| 2009年05月08日 |
Multiple cross site scripting issues |
<= 1.4.17 |
0 |
CVE-2009-1578 |
| 2008年12月04日 |
Cross site scripting in HTML filter |
1.4.0 - 1.4.16 |
0 |
CVE-2008-2379 |
| 2008年09月28日 |
Cookies for SSL connection could be sent over non-SSL |
1.4.0 - 1.4.15 |
0 |
CVE-2008-3663 |
| 2007年12月13日 |
1.4.12 and 1.4.11 Package Compromise |
1.4.11&12 |
0 |
CVE-2007-6348 |
| 2007年05月09日 |
Cross site scripting in HTML filter |
1.4.0-1.4.9a |
0 |
CVE-2007-1262, CVE-2007-2589 |
| 2006年12月03日 |
Workaround for Internet Explorer MIME handling |
IE |
0 |
| 2006年12月02日 |
Cross site scripting in compose, draft & HTML mail viewing |
1.4.0 - 1.4.9 |
0 |
CVE-2006-6142 |
| 2006年08月11日 |
Variable overwriting in compose.php |
1.4.0 - 1.4.7 |
0 |
CVE-2006-4019 |
| 2006年06月22日 |
Disputed: search.php cross site scripting |
none |
1 |
CVE-2006-3174 |
| 2006年06月01日 |
Local file inclusion |
<= 1.4.6 |
1 |
CVE-2006-2842 |
| 2006年02月15日 |
IMAP injection in sqimap_mailbox_select mailbox parameter |
<= 1.4.5 |
0 |
CVE-2006-0377 |
| 2006年02月10日 |
Possible XSS in MagicHTML (IE only) |
<= 1.4.5 |
0 |
CVE-2006-0195 |
| 2006年02月01日 |
Possible XSS through right_frame parameter in webmail.php |
<= 1.4.5 |
0 |
CVE-2006-0188 |
| 2005年07月13日 |
$_POST variable handling in options_identites allows for different attacks |
<= 1.4.5-RC1 |
1 |
CVE-2005-2095 |
| 2005年06月15日 |
Several cross site scripting vulnerabilities |
<= 1.4.4 |
0 |
CVE-2005-1769 |
| 2005年01月20日 |
XSS vulnerability in webmail.php |
<= 1.4.4-RC1 |
0 |
CVE-2005-0104 |
| 2005年01月19日 |
Frame content changing in webmail.php |
<= 1.4.4-RC1 |
0 |
CVE-2005-0103 |
| 2005年01月14日 |
Local file inclusions in prefs.php |
1.4.3-RC1 - 1.4.4-RC1 |
1 |
CVE-2005-0075 |
| 2004年11月10日 |
XSS vulnerability in decodeHeader() |
<= 1.4.3a |
0 |
CVE-2004-1036 |
| 2004年05月30日 |
XSS vulnerability in Content-Type display in read_body |
<= 1.4.3-RC1 |
0 |
| 2004年05月10日 |
SQL injection vulnerability in addressbook |
<= 1.4.2 |
0 |
CVE-2004-0521 |
| 2004年05月01日 |
Multiple XSS vulnerabilities |
<= 1.4.2 |
0 |
CVE-2004-0519, CVE-2004-0520 |
| 2004年04月03日 |
XSS vulnerability in incoming email headers |
<= 1.4.0-RC2a |
0 |
| 2004年04月01日 |
XSS vulnerability when replying to malicious sources |
<= 1.4.0-RC2a |
0 |
The column RG indicates whether the vulnerability only applies to systems that
have the PHP register_globals setting turned On, something that is highly discouraged
by both PHP and the SquirrelMail team.
CVE IDs are used for cross-referencing security issues between distributions.
This page only lists known issues since the start of the 1.4.0 Stable series.
Website Bug Reports
We'd like to express much gratitude to reporters of bugs with our website as follows:
- Murat Yılmazlar - https://tr.linkedin.com/in/muratyilmazlarr
- Balaji P R - https://www.linkedin.com/in/balagpy
- Stef
- Ashish Pathak - https://twitter.com/pathakbackz
- דביר לוי
- Thomas Chauchefoin
|