Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2009-0030
Description:A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic circumstances by using the standard webmail.php interface. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3663.
Test IDs: 1.3.6.1.4.1.25623.1.0.63244   1.3.6.1.4.1.25623.1.0.880829   1.3.6.1.4.1.25623.1.0.63192   1.3.6.1.4.1.25623.1.0.880718   1.3.6.1.4.1.25623.1.0.880925  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2009-0030
1021611
http://securitytracker.com/id?1021611
33354
http://www.securityfocus.com/bid/33354
33611
http://secunia.com/advisories/33611
RHSA-2009:0057
https://rhn.redhat.com/errata/RHSA-2009-0057.html
SUSE-SR:2009:004
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
https://bugzilla.redhat.com/show_bug.cgi?id=480224
https://bugzilla.redhat.com/show_bug.cgi?id=480224
https://bugzilla.redhat.com/show_bug.cgi?id=480488
https://bugzilla.redhat.com/show_bug.cgi?id=480488
oval:org.mitre.oval:def:10366
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10366
squirrelmail-sessionid-session-hijacking(48115)
https://exchange.xforce.ibmcloud.com/vulnerabilities/48115




© 1998-2025 E-Soft Inc. All rights reserved.