[27129] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Squirrel Mail 1.2.7 XSS Exploit

daemon@ATHENA.MIT.EDU (Jason Munro)
Thu Sep 19 20:22:08 2002

Message-ID: <15818.63.161.72.14.1032472269.squirrel@mail.stdbev.com>
Date: Thu, 19 Sep 2002 16:51:09 -0500 (CDT)
From: "Jason Munro" <jason@stdbev.com>
To: <bugtraq@securityfocus.com>
In-Reply-To: <000301c26021$9328b120$1fff3cd8@dsc.k12.ar.us>
Reply-To: jason@stdbev.com
MIME-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 8bit

DarC KonQuesT said:
> ****Sorry if you receive two of these.****
>
> DarC KonQuesT XSS Release-
>
> Product: Squirrel Mail 1.2.7 - released June 21, 2002 (tested, others
> possibly vulnerable)
> Vendor: Squirrel Mail - Web: www.squirrelmail.org
> Problem: Cross Site Scripting
> Severity: Moderate
> Operating System(s): Tested against Red Hat 7.3, all others vulnerable
> if they are using this version of Squirrel.

Mr KonQuesT,
  All the listed exploits have been fixed in the recently released 1.2.8
version of SquirrelMail. These fixes have also been applied to the
current development and stable CVS, 1.3.2 and 1.2.9 respectively.


 \___ Jason Munro
  \___ AIM:jmunr0
   \__ jason@stdbev.com
    \__ http://www.sunflower.com/~jmunro/



home help back first fref pref prev next nref lref last post