LWN.net Logo

squirrelmail: cross-site request forgery

Package(s):squirrelmail CVE #(s):
Created:August 21, 2009 Updated:August 26, 2009
Description: From the Red Hat bugzilla: It was reported that SquirrelMail did not implement protections against cross-site request forgery (CSRF) attacks. This can be exploited to e.g. change user preferences, delete emails, and potentially send emails when a logged-in user visits a malicious web page.
Alerts:
Fedora FEDORA-2009-8822 2009-08-20
Fedora FEDORA-2009-8797 2009-08-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds