← All CVEs

CVE-2002-1131

high · 7.5

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php.

7.5
CVSS
25.6%
EPSS (exploit prob.)
98th
EPSS percentile
2002-10-04
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
squirrelmailsquirrelmail<= 1.2.7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-1131