看板
[ Bugtraq ]
討論串squirrelmail CSRF vulnerability
共 5 篇文章
內容預覽:
On Sat, 12 May 2007, Josh Zlatin-Amishav wrote:. > On Fri, 11 May 2007, Tim Newsham wrote:. >. > > This might just be semantics: I wouldn't consider t
(還有593個字)
內容預覽:
On Fri, 11 May 2007, Tim Newsham wrote:. >> 1.4.8-4 is vulnerable to a XSS vulnerability, so an attacker could use the>> XSS vector to grab the sessio
(還有595個字)
內容預覽:
>> II. Application should use CSRF token which is random enough to identify>> every legitimate post login request.. >. > According to: http://squirrel
(還有662個字)
內容預覽:
On Thu, 10 May 2007 p3rlhax@gmail.com wrote:. > IV. DETECTION. >. > Latest version of squirrel mail 1.4.8-4.fc6 and prior are found vulnerable.>. > V.
(還有401個字)
內容預覽:
I. BACKGROUND. SquirrelMail is a standards-based webmail package written in PHP.. It includes built-in pure PHP support for the IMAP and SMTP protocol
(還有2733個字)