2024-07-14 02:06:08 +00:00

276 lines
8.6 KiB
JSON

{
"id": "CVE-2004-0519",
"sourceIdentifier": "cve@mitre.org",
"published": "2004-08-18T04:00:00.000",
"lastModified": "2017-10-11T01:29:27.230",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php."
},
{
"lang": "es",
"value": "Multiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en SquirrelMail 1.4.2 permiten a atacantes remotos ejecutar script de su elecci\u00f3n como otro usuario y posiblemente robar informaci\u00f3n de autenticaci\u00f3n mediante m\u00faltiples vectores de ataque, incluyendo el par\u00e1metro mailbox en compose.php."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sgi:propack:3.0:*:*:*:*:*:*:*",
"matchCriteriaId": "29DC217F-C257-4A3C-9CBD-08010C30BEC3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.0.4:*:*:*:*:*:*:*",
"matchCriteriaId": "67E9817E-FF56-4FD0-B6C7-F4EEB25AD0CF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.0.5:*:*:*:*:*:*:*",
"matchCriteriaId": "5EBF40C5-6272-427C-97A1-3CE3B1D47B12"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "A55A98B3-34ED-4A90-BB78-50CB56B1B51F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.1:*:*:*:*:*:*:*",
"matchCriteriaId": "CC5143ED-D4C5-4830-9C96-0B54D03679CB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.2:*:*:*:*:*:*:*",
"matchCriteriaId": "9B765AEC-09E9-456C-8B57-09927E55D119"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.3:*:*:*:*:*:*:*",
"matchCriteriaId": "0AAFC3B0-DCE3-4190-B279-E095C666FA34"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.4:*:*:*:*:*:*:*",
"matchCriteriaId": "9291A565-0BD6-4B5E-B45F-9DE65AB8159D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.5:*:*:*:*:*:*:*",
"matchCriteriaId": "B6F53A84-FC66-4963-A728-7285F63D4761"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.6:*:*:*:*:*:*:*",
"matchCriteriaId": "69A941FF-423E-49C5-AE1F-FE7ED016CA3D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.7:*:*:*:*:*:*:*",
"matchCriteriaId": "B34FDB1D-881B-4343-A76E-F23B93A0469A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.8:*:*:*:*:*:*:*",
"matchCriteriaId": "1E4DCB20-2A7F-4EE4-BAFA-AD74CD4456AB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.9:*:*:*:*:*:*:*",
"matchCriteriaId": "052914F8-B52C-4AB4-8F85-68D788B588C9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.10:*:*:*:*:*:*:*",
"matchCriteriaId": "617C554F-8E7D-4F8A-AF63-C193934C8215"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.2.11:*:*:*:*:*:*:*",
"matchCriteriaId": "15F11950-A2E4-4F57-BF87-57788B841A21"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4:*:*:*:*:*:*:*",
"matchCriteriaId": "026730B8-3919-4100-8607-C640ADBDD662"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4.1:*:*:*:*:*:*:*",
"matchCriteriaId": "4AD31177-05BB-4623-AED7-765DB7E44E47"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squirrelmail:squirrelmail:1.4.2:*:*:*:*:*:*:*",
"matchCriteriaId": "20247A22-9AB9-4BCE-BF28-350B52FBC62D"
}
]
}
]
}
],
"references": [
{
"url": "ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000858",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=108334862800260",
"source": "cve@mitre.org"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2004-240.html",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/11531",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/11686",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/11870",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/12289",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://security.gentoo.org/glsa/glsa-200405-16.xml",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.debian.org/security/2004/dsa-535",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://www.novell.com/linux/security/advisories/2005_19_sr.html",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/advisories/6827",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/archive/1/361857",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/10246",
"source": "cve@mitre.org",
"tags": [
"Exploit",
"Patch"
]
},
{
"url": "https://bugzilla.fedora.us/show_bug.cgi?id=1733",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/16025",
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1006",
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10274",
"source": "cve@mitre.org"
}
]
}