Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-0519. PoCs published by Alvin Alex. A Nuclei detection template is also available.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in SquirrelMail due to improper sanitization of user-supplied input in folder name displays. The example URL demonstrates how an attacker could inject malicious JavaScript to steal cookie-based authentication credentials.
Description
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in SquirrelMail due to improper sanitization of user-supplied input in folder name displays. The example URL demonstrates how an attacker could inject malicious JavaScript to steal cookie-based authentication credentials.