Bug 123011
Summary: | More squirrelmail XSS issues | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Mark J. Cox <mjc> |
Component: | squirrelmail | Assignee: | Gary Benson <gbenson> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 2 | CC: | k.georgiou |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2004-06-09 15:32:15 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Mark J. Cox
2004-05-11 09:52:21 UTC
- Fix some XSS issues. (in 1.4.3 RC1) in CVS as: http://marc.theaimsgroup.com/?l=squirrelmail-cvs&m=108232045127038 http://marc.theaimsgroup.com/?l=squirrelmail-cvs&m=108232039707209 http://marc.theaimsgroup.com/?l=squirrelmail-cvs&m=108231961004190 http://marc.theaimsgroup.com/?l=squirrelmail-cvs&m=108231673730889 http://marc.theaimsgroup.com/?l=squirrelmail-cvs&m=108231643021211 - Fixed XSS vulnerability in content-type display in the attachment area of read_body.php discovered by Roman Medina. (since 1.4.3 RC1) http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-1.txt http://marc.theaimsgroup.com/?l=squirrelmail-cvs&m=108532891231712 - Unspecified SQL injection attack http://marc.theaimsgroup.com/?l=squirrelmail-devel&m=108424284608500 is actually "SQL injection attack in personal addressbook database class" http://marc.theaimsgroup.com/?l=squirrelmail-cvs&m=108309375029888 |