CVE-2011-2752

SquirrelMail < 1.4.21 - CRLF Injection via Newline Character

Title source: llm
STIX 2.1

Description

CRLF injection vulnerability in SquirrelMail 1.4.21 and earlier allows remote attackers to modify or add preference values via a \n (newline) character, a different vulnerability than CVE-2010-4555.

References (5)

Core 5
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2291
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/68587
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2011:123
Patch, Vendor Advisory x_refsource_confirm
http://www.squirrelmail.org/security/issue/2011-07-11
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-0103.html

Scores

EPSS 0.0193
EPSS Percentile 77.6%

Details

CWE
CWE-94
Status published
Products (47)
squirrelmail/squirrelmail 0.1
squirrelmail/squirrelmail 0.1.1
squirrelmail/squirrelmail 0.1.2
squirrelmail/squirrelmail 0.2
squirrelmail/squirrelmail 0.2.1
squirrelmail/squirrelmail 0.3
squirrelmail/squirrelmail 0.3.1
squirrelmail/squirrelmail 0.3pre1
squirrelmail/squirrelmail 0.3pre2
squirrelmail/squirrelmail 0.4
... and 37 more
Published Jul 17, 2011
Tracked Since Feb 18, 2026