CVE-2009-0030
Last modified
CVE-2009-0030 is a vulnerability of currently unknown severity. A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic circumstances by using the standard webmail.php interface. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3663.. EPSS estimates a 1.68% chance of exploitation in the next 30 days.
Description
A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic circumstances by using the standard webmail.php interface. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3663.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Squirrelmail | Squirrelmail | 1.4.8 |
References
- http://secunia.com/advisories/33611Vendor Advisory
- http://secunia.com/advisories/33611Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0030?
How severe is CVE-2009-0030?
How do I fix CVE-2009-0030?
Are you affected by CVE-2009-0030?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
