CVE-2002-1131
high · 7.5A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php.
7.5
CVSS
25.6%
EPSS (exploit prob.)
98th
EPSS percentile
2002-10-04
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| squirrelmail | squirrelmail | <= 1.2.7 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0246.html
- http://sourceforge.net/project/shownotes.php?group_id=311&release_id=110774
- http://www.debian.org/security/2002/dsa-191
- http://www.iss.net/security_center/static/10145.php
- http://www.redhat.com/support/errata/RHSA-2002-204.html
- http://www.securityfocus.com/bid/5763
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0246.html
- http://sourceforge.net/project/shownotes.php?group_id=311&release_id=110774
- http://www.debian.org/security/2002/dsa-191
- http://www.iss.net/security_center/static/10145.php
- http://www.redhat.com/support/errata/RHSA-2002-204.html
- http://www.securityfocus.com/bid/5763
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2002-1131