SquirrelMail "Address Add" Plugin Vulnerable to Cross Site Scripting

A plug-in forSquirrelMail, Address Add, is vulnerable to cross-site scriptingattacks. A successful attack might allow an intruder to obtain a person's cookie and session information

ITPro Today

September 29, 2005

1 Min Read
ITPro Today logo

ReportedSeptember 28, 2005 by Moritz Naumann

VERSIONS AFFECTED

SquirrelMail“Address Add” Plugin, version 1.4 to 2.0


DESCRIPTION

SquirrelMailis a popular cross-platform Web-based email interface. A plug-in forSquirrelMail, Address Add, is vulnerable to cross-site scriptingattacks. A successful attack might allow an intruder to obtain aperson's cookie and session information.

VENDOR RESPONSE

The plug-in'sdeveloper, Jimmy Conner, has released AddressAdd 2.1, whichcorrects this problem. Administrators who use the plug-in shouldupgrade to this version. If an upgrade isn't possible, ensure thatusers have Javascript disabled in their browsers or that the AddressAdd plug-in is disabled.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like