squirrelmail: cross-site request forgery
| Package(s): | squirrelmail | CVE #(s): | |||||||||
| Created: | August 21, 2009 | Updated: | August 26, 2009 | ||||||||
| Description: | From the Red Hat bugzilla: It was reported that SquirrelMail did not implement protections against cross-site request forgery (CSRF) attacks. This can be exploited to e.g. change user preferences, delete emails, and potentially send emails when a logged-in user visits a malicious web page. | ||||||||||
| Alerts: |
| ||||||||||
