CVE-2010-4555
Squirrelmail < 1.4.21 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) drop-down selection lists, (2) the > (greater than) character in the SquirrelSpell spellchecking plugin, and (3) errors associated with the Index Order (aka options_order) page.
References (10)
Scores
EPSS
0.0089
EPSS Percentile
75.4%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
squirrelmail/squirrelmail
< 1.4.21
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
squirrelmail/squirrelmail
... and 35 more
Timeline
Published
Jul 14, 2011
Tracked Since
Feb 18, 2026