CVE-2002-1276

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/11/2002
Last modified:
03/04/2025

Description

An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving it open to cross-site scripting attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:squirrelmail:squirrelmail:1.2.8:*:*:*:*:*:*:*