Candidate: CVE-2010-4555 PublicDate: 2011-07-14 23:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4555 http://www.squirrelmail.org/security/issue/2011-07-11 Description: Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) drop-down selection lists, (2) the > (greater than) character in the SquirrelSpell spellchecking plugin, and (3) errors associated with the Index Order (aka options_order) page. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_squirrelmail: upstream: http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=revision&revision=14119 upstream_squirrelmail: released (1.4.22) hardy_squirrelmail: ignored (reached end-of-life) lucid_squirrelmail: ignored (reached end-of-life) maverick_squirrelmail: ignored (reached end-of-life) natty_squirrelmail: ignored (reached end-of-life) oneiric_squirrelmail: not-affected (2:1.4.22-1) precise_squirrelmail: not-affected (2:1.4.22-1) quantal_squirrelmail: not-affected (2:1.4.22-1) raring_squirrelmail: not-affected (2:1.4.22-1) saucy_squirrelmail: not-affected (2:1.4.22-1) devel_squirrelmail: not-affected (2:1.4.22-1)