|
|
| |
|
| |
squirrelmail: cross-site request forgery
| Package(s): | squirrelmail |
CVE #(s): | |
| Created: | August 21, 2009 |
Updated: | August 26, 2009 |
| Description: |
From the Red
Hat bugzilla: It was reported that SquirrelMail did not implement
protections against cross-site request forgery (CSRF) attacks. This can be
exploited to e.g. change user preferences, delete emails, and potentially
send emails when a logged-in user visits a malicious web page. |
| Alerts: |
|
( Log in to post comments)
|
|
|