Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2009-2964

Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.19 and earlier, and NaSMail before 1.7, allow remote attackers to hijack the authentication of unspecified victims via features such as send message and change preferences, related to (1) functions/mailbox_display.php, (2) src/addrbook_search_html.php, (3) src/addressbook.php, (4) src/compose.php, (5) src/folders.php, (6) src/folders_create.php, (7) src/folders_delete.php, (8) src/folders_rename_do.php, (9) src/folders_rename_getname.php, (10) src/folders_subscribe.php, (11) src/move_messages.php, (12) src/options.php, (13) src/options_highlight.php, (14) src/options_identities.php, (15) src/options_order.php, (16) src/search.php, and (17) src/vcard.php.

  • Published: Aug 25, 2009
  • Updated: Apr 13, 2023
  • CVE: CVE-2009-2964
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
squirrelmail / squirrelmail 1.3.1 1.3.1.x
squirrelmail / squirrelmail 1.4.2 1.4.2.x
squirrelmail / squirrelmail 1.4.5_rc1 1.4.5_rc1.x
squirrelmail / squirrelmail 1.0.6 1.0.6.x
squirrelmail / squirrelmail 1.0.5 1.0.5.x
squirrelmail / squirrelmail 1.4.17 1.4.17.x
squirrelmail / squirrelmail 1.2.0-rc3 1.2.0-rc3.x
squirrelmail / squirrelmail 1.1.0 1.1.0.x
squirrelmail / squirrelmail 1.4.6_rc1 1.4.6_rc1.x
squirrelmail / squirrelmail 1.0pre2 1.0pre2.x
squirrelmail / squirrelmail 1.4.3_r3 1.4.3_r3.x
squirrelmail / squirrelmail 1.4.0-r1 1.4.0-r1.x
squirrelmail / squirrelmail 0.1.2 0.1.2.x
squirrelmail / squirrelmail 1.2.7 1.2.7.x
squirrelmail / squirrelmail 1.4.13 1.4.13.x
squirrelmail / squirrelmail 1.0.1 1.0.1.x
squirrelmail / squirrelmail 1.2.6-rc1 1.2.6-rc1.x
squirrelmail / squirrelmail 1.4.12 1.4.12.x
squirrelmail / squirrelmail 1.4.9a 1.4.9a.x
squirrelmail / squirrelmail 1.4.6 1.4.6.x
squirrelmail / squirrelmail 1.4.3-r3 1.4.3-r3.x
squirrelmail / squirrelmail 1.2.0 1.2.0.x
squirrelmail / squirrelmail 1.4.7 1.4.7.x
squirrelmail / squirrelmail 1.2.9 1.2.9.x
squirrelmail / squirrelmail 1.4.3_rc1 1.4.3_rc1.x
squirrelmail / squirrelmail 1.4.15 1.4.15.x
squirrelmail / squirrelmail 1.2.2 1.2.2.x
squirrelmail / squirrelmail 1.4.2-r3 1.4.2-r3.x
squirrelmail / squirrelmail 1.1.1 1.1.1.x
squirrelmail / squirrelmail 1.4.4_rc1 1.4.4_rc1.x
squirrelmail / squirrelmail 1.4.16 1.4.16.x
squirrelmail / squirrelmail 1.2.0_rc3 1.2.0_rc3.x
squirrelmail / squirrelmail 1.4-rc1 1.4-rc1.x
squirrelmail / squirrelmail 1.1.2 1.1.2.x
squirrelmail / squirrelmail 1.4.15_rc1 1.4.15_rc1.x
squirrelmail / squirrelmail 1.4.2-r5 1.4.2-r5.x
squirrelmail / squirrelmail 1.4.4-rc1 1.4.4-rc1.x
squirrelmail / squirrelmail 1.4.15rc1 1.4.15rc1.x
squirrelmail / squirrelmail 1.4.3 1.4.3.x
squirrelmail / squirrelmail 0.1.1 0.1.1.x
squirrelmail / squirrelmail 1.3.2 1.3.2.x
squirrelmail / squirrelmail 1.4.3-rc1 1.4.3-rc1.x
squirrelmail / squirrelmail 1.2.1 1.2.1.x
squirrelmail / squirrelmail 1.4.1 1.4.1.x
squirrelmail / squirrelmail 1.4.9 1.4.9.x
squirrelmail / squirrelmail 1.2 1.2.x
squirrelmail / squirrelmail 1.4.0_rc2a 1.4.0_rc2a.x
squirrelmail / squirrelmail 1.4.8 1.4.8.x
squirrelmail / squirrelmail 1.4.0_rc1 1.4.0_rc1.x
squirrelmail / squirrelmail 1.4.6_cvs 1.4.6_cvs.x
squirrelmail / squirrelmail 1.4.0 1.4.0.x
squirrelmail / squirrelmail 1.4.0-rc1 1.4.0-rc1.x
squirrelmail / squirrelmail 1.4 1.4.x
squirrelmail / squirrelmail 1.1.3 1.1.3.x
squirrelmail / squirrelmail 1.4.0-rc2a 1.4.0-rc2a.x
squirrelmail / squirrelmail 1.2.4 1.2.4.x
squirrelmail / squirrelmail 1.2.3 1.2.3.x
squirrelmail / squirrelmail 1.4.10 1.4.10.x
squirrelmail / squirrelmail 1.4.3a 1.4.3a.x
squirrelmail / squirrelmail 1.4.2-r1 1.4.2-r1.x
squirrelmail / squirrelmail 1.0.2 1.0.2.x
squirrelmail / squirrelmail 1.0.4 1.0.4.x
squirrelmail / squirrelmail 1.4.6-rc1 1.4.6-rc1.x
squirrelmail / squirrelmail 1.0pre1 1.0pre1.x
squirrelmail / squirrelmail 1.4_rc1 1.4_rc1.x
squirrelmail / squirrelmail 1.2.6 1.2.6.x
squirrelmail / squirrelmail 1.4.15-rc1 1.4.15-rc1.x
squirrelmail / squirrelmail 1.4.2-r2 1.4.2-r2.x
squirrelmail / squirrelmail 1.4.8.4fc6 1.4.8.4fc6.x
squirrelmail / squirrelmail 1.4.10a 1.4.10a.x
squirrelmail / squirrelmail 1.4.4 1.4.4.x
squirrelmail / squirrelmail 1.4.2-r4 1.4.2-r4.x
squirrelmail / squirrelmail 1.4.18 1.4.18.x
squirrelmail / squirrelmail 1.4.3aa 1.4.3aa.x
squirrelmail / squirrelmail 1.2.10 1.2.10.x
squirrelmail / squirrelmail 1.2.5 1.2.5.x
squirrelmail / squirrelmail 1.4.11 1.4.11.x
squirrelmail / squirrelmail 1.0.3 1.0.3.x
squirrelmail / squirrelmail 1.3.0 1.3.0.x
squirrelmail / squirrelmail 1.0 1.0.x
squirrelmail / squirrelmail 1.2.8 1.2.8.x
squirrelmail / squirrelmail 1.2.11 1.2.11.x
squirrelmail / squirrelmail 1.4.5 1.4.5.x
squirrelmail / squirrelmail - 1.4.19.x
squirrelmail / squirrelmail 1.0pre3 1.0pre3.x
squirrelmail / squirrelmail 1.4.3_rc1-r1 1.4.3_rc1-r1.x