CVE-2005-2095

Description

From CVE.org

options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to modify or read the preferences of other users, conduct cross-site scripting XSS) attacks, and write arbitrary files.

Frequently Asked Questions

Want to get errata notifications? Sign up here.