peter bassill · operator
$ cve CVE-2002-1131 JSON

CVE-2002-1131 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 25.8% (pctl 98)

Patch early

A public exploit exists.

Description

Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS25.75% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2002-10-04
Last modified2026-06-16

Affected (1)

VendorProduct
squirrelmailsquirrelmail

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD