peter bassill · operator
$ cve CVE-2004-0519 JSON

CVE-2004-0519 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 22.5% (pctl 98)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS22.53% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2004-08-18
Last modified2026-06-16

Affected (2)

VendorProduct
sgipropack
squirrelmailsquirrelmail

Public exploits

SourceTitleDate
exploit-dbSquirrelMail 1.4.x - Folder Name Cross-Site Scripting2004-04-30

References

→ the Explorer  ·  watch your stack  ·  NVD