Lucene search

K
cveMitreCVE-2005-0075
HistoryFeb 06, 2005 - 5:00 a.m.

CVE-2005-0075

2005-02-0605:00:00
mitre
web.nvd.nist.gov
69
squirrelmail
code injection
security vulnerability
cve-2005-0075
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.006

Percentile

78.7%

prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.

Affected configurations

Nvd
Node
squirrelmailsquirrelmailMatch1.0.4
OR
squirrelmailsquirrelmailMatch1.0.5
OR
squirrelmailsquirrelmailMatch1.2.0
OR
squirrelmailsquirrelmailMatch1.2.1
OR
squirrelmailsquirrelmailMatch1.2.2
OR
squirrelmailsquirrelmailMatch1.2.3
OR
squirrelmailsquirrelmailMatch1.2.4
OR
squirrelmailsquirrelmailMatch1.2.5
OR
squirrelmailsquirrelmailMatch1.2.6
OR
squirrelmailsquirrelmailMatch1.2.7
OR
squirrelmailsquirrelmailMatch1.2.8
OR
squirrelmailsquirrelmailMatch1.2.9
OR
squirrelmailsquirrelmailMatch1.2.10
OR
squirrelmailsquirrelmailMatch1.2.11
OR
squirrelmailsquirrelmailMatch1.4
OR
squirrelmailsquirrelmailMatch1.4.0
OR
squirrelmailsquirrelmailMatch1.4.1
OR
squirrelmailsquirrelmailMatch1.4.2
OR
squirrelmailsquirrelmailMatch1.4.3
OR
squirrelmailsquirrelmailMatch1.4.3a
VendorProductVersionCPE
squirrelmailsquirrelmail1.0.4cpe:2.3:a:squirrelmail:squirrelmail:1.0.4:*:*:*:*:*:*:*
squirrelmailsquirrelmail1.0.5cpe:2.3:a:squirrelmail:squirrelmail:1.0.5:*:*:*:*:*:*:*
squirrelmailsquirrelmail1.2.0cpe:2.3:a:squirrelmail:squirrelmail:1.2.0:*:*:*:*:*:*:*
squirrelmailsquirrelmail1.2.1cpe:2.3:a:squirrelmail:squirrelmail:1.2.1:*:*:*:*:*:*:*
squirrelmailsquirrelmail1.2.2cpe:2.3:a:squirrelmail:squirrelmail:1.2.2:*:*:*:*:*:*:*
squirrelmailsquirrelmail1.2.3cpe:2.3:a:squirrelmail:squirrelmail:1.2.3:*:*:*:*:*:*:*
squirrelmailsquirrelmail1.2.4cpe:2.3:a:squirrelmail:squirrelmail:1.2.4:*:*:*:*:*:*:*
squirrelmailsquirrelmail1.2.5cpe:2.3:a:squirrelmail:squirrelmail:1.2.5:*:*:*:*:*:*:*
squirrelmailsquirrelmail1.2.6cpe:2.3:a:squirrelmail:squirrelmail:1.2.6:*:*:*:*:*:*:*
squirrelmailsquirrelmail1.2.7cpe:2.3:a:squirrelmail:squirrelmail:1.2.7:*:*:*:*:*:*:*
Rows per page:
1-10 of 201

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.006

Percentile

78.7%