CVE-2007-1262 describes multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail versions 1.4.0 through 1.4.9a. These flaws allow remote attackers to inject arbitrary web script or HTML, either through a data: URI in an HTML email attachment or via improperly filtered non-ASCII character sets when viewed with Microsoft Internet Explorer. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity leading to partial integrity impact, but no confidentiality or availability impact. There is no evidence of active exploitation, no known exploit code in common databases like Metasploit or ExploitDB, and it has received negligible community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.0CPE matchmatch criteria | cpe:2.3:a:squirrelmail:squirrelmail:1.4.0:*:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:a:squirrelmail:squirrelmail:1.4.1:*:*:*:*:*:*:* | ||
1.4.2CPE matchmatch criteria | cpe:2.3:a:squirrelmail:squirrelmail:1.4.2:*:*:*:*:*:*:* | ||
1.4.3CPE matchmatch criteria | cpe:2.3:a:squirrelmail:squirrelmail:1.4.3:*:*:*:*:*:*:* | ||
1.4.3_r3CPE matchmatch criteria | cpe:2.3:a:squirrelmail:squirrelmail:1.4.3_r3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.