Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

SquirrelMail < 1.4.4 decodeHeader HTML Injection

Medium

Synopsis

The remote host allows attackers to bypass user authentication.

Description

The remote host is running SquirrelMail, a webmail system written in PHP. Versions of SquirrelMail prior to 1.4.4 are vulnerable to an email HTML injection vulnerability. A remote attacker can exploit this flaw to gain access to users' accounts.

Solution

Upgrade to SquirrelMail 1.4.4 or higher.