CVE-2009-1580

Squirrelmail < 1.4.17 - Authentication Bypass

Title source: rule

Description

Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie.

References (20)

Scores

EPSS 0.0103
EPSS Percentile 77.1%

Classification

CWE
CWE-287
Status draft

Affected Products (50)

squirrelmail/squirrelmail < 1.4.17
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
... and 35 more

Timeline

Published May 14, 2009
Tracked Since Feb 18, 2026