Entries Categorized as 'Email Systems'

A flaw in Google’s G-Mail system allowed anyone access to any mailbox

Date December 3, 2005

This bug has already been corrected, that’s why it’s been published.
In this manual you will see step by step how to exploit Gmail’s
vulnerability, that gave you access to any account, reported by
Anelkaos, colaborator of elhacker.net’s forum and patched by Google by
October 18. Due to the bug’s gravity (that allowed in a few simple steps
to login [...]

SquirrelMail Arbitrary Variable Overwriting Vulnerability

Date July 15, 2005

Vendor : The SquirrelMail Project Team
URL : http://www.squirrelmail.org/
Version : SquirrelMail 1.4.5-RC1 && Earlier
Risk : Variable Overwriting
Description:
SquirrelMail is a standards-based webmail package written in php. It
includes built-in pure PHP support for the IMAP and SMTP protocols.
Unfortunately there is a fairly serious variable handling issue in one
of the core [...]

Updated squirrelmail packages fix XSS vulnerabilities

Date July 2, 2005

Package name: squirrelmail
Advisory ID: MDKSA-2005:108
Date: June 30th, 2005
Affected versions: Corporate 3.0
Problem [...]