CVE-2010-1637

MEDIUM

Squirrelmail < 1.4.20 - SSRF

Title source: rule

Description

The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number.

References (20)

Scores

CVSS v3 6.5
EPSS 0.0061
EPSS Percentile 69.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-918
Status draft

Affected Products (9)

squirrelmail/squirrelmail < 1.4.20
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
apple/mac_os_x < 10.6.8
apple/mac_os_x_server < 10.6.8
redhat/enterprise_linux_desktop
redhat/enterprise_linux_server
redhat/enterprise_linux_workstation

Timeline

Published Jun 22, 2010
Tracked Since Feb 18, 2026