VDB
CVE-2004-0521
CVE-2004-0521
PUBLISHED
CVSS 10 CRITICAL
SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php.
EPSS 3.15% · 86.9th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
3.15%
86.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| squirrelmail | squirrelmail | 1.0.4, 1.2.0, 1.2.1 |
| sgi | propack | 3.0 |
Timeline
- Jun 3, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Dec 23, 2023 EPSS Score
References
- 11686 third-party-advisory
- RHSA-2004:240 vendor-advisory
- [squirrelmail-devel] 20040511 [SM-DEVEL] SquirrelMail 1.4.3-RC1 Release mailing-list
- 20040604-01-U vendor-advisory
- CLA-2004:858 vendor-advisory
- 11685 third-party-advisory
- DSA-535 vendor-advisory
- oval:org.mitre.oval:def:1033 vdb
- APPLE-SA-2004-09-07 vendor-advisory
- http://www.ciac.org/ciac/bulletins/o-212.shtml technical
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16235 technical
- http://marc.info/?l=squirrelmail-cvs&m=108309375029888 technical
- http://secunia.com/advisories/12289 technical
- http://security.gentoo.org/glsa/glsa-200405-16.xml advisory
- http://www.osvdb.org/6841 technical
- https://nvd.nist.gov/vuln/detail/CVE-2004-0521 advisory
- https://bugzilla.fedora.us/show_bug.cgi?id=1733 url
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11446 url
- http://secunia.com/advisories/11870 url
- http://www.securityfocus.com/advisories/6827 url
…and 1 more