Total vulnerabilities in the database
Cross-site scripting (XSS) vulnerability in search.php in SquirrelMail 1.5.1 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary HTML via the mailbox parameter.
Software | From | Fixed in |
---|---|---|
squirrelmail / squirrelmail | - | 1.5.1.x |