CVE-2011-2752
SquirrelMail < 1.4.21 - CRLF Injection via Newline Character
Title source: llmDescription
CRLF injection vulnerability in SquirrelMail 1.4.21 and earlier allows remote attackers to modify or add preference values via a \n (newline) character, a different vulnerability than CVE-2010-4555.
References (5)
Core 5
Core References
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2011/dsa-2291
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/68587
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2011:123
Patch, Vendor Advisory x_refsource_confirm
http://www.squirrelmail.org/security/issue/2011-07-11
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-0103.html
Scores
EPSS
0.0193
EPSS Percentile
77.6%
Details
CWE
CWE-94
Status
published
Products (47)
squirrelmail/squirrelmail
0.1
squirrelmail/squirrelmail
0.1.1
squirrelmail/squirrelmail
0.1.2
squirrelmail/squirrelmail
0.2
squirrelmail/squirrelmail
0.2.1
squirrelmail/squirrelmail
0.3
squirrelmail/squirrelmail
0.3.1
squirrelmail/squirrelmail
0.3pre1
squirrelmail/squirrelmail
0.3pre2
squirrelmail/squirrelmail
0.4
... and 37 more
Published
Jul 17, 2011
Tracked Since
Feb 18, 2026