CVE-2005-3128
EXPLOITED NUCLEIAddress Add Plugin <2.0 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in add.php in Address Add Plugin 1.9 and 2.0 for Squirrelmail allows remote attackers to inject arbitrary web script or HTML via the IMG tag.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by anonymous · textwebappsphp
https://www.exploit-db.com/exploits/26305
Nuclei Templates (1)
SquirrelMail Address Add 1.4.2 - Cross-Site Scripting
MEDIUMVERIFIEDby dhiyaneshDk
References (13)
Scores
EPSS
0.0197
EPSS Percentile
83.6%
Details
VulnCheck KEV
2024-09-19
Status
published
Products (2)
squirrelmail/address_add_plugin
1.9
squirrelmail/address_add_plugin
2.0
Published
Oct 04, 2005
Tracked Since
Feb 18, 2026