CVE-2007-2589

Publication date 11 May 2007

Last updated 17 July 2025


Ubuntu priority

Description

Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail 1.4.0 through 1.4.9a allows remote attackers to send e-mails from arbitrary users via certain data in the SRC attribute of an IMG element.

Status

Package Ubuntu Release Status
squirrelmail 7.04 feisty
Fixed 1.4.9a-1ubuntu0.1
6.10 edgy
Fixed 1.4.8-1ubuntu0.1
6.06 LTS dapper
Fixed 1.4.6-1ubuntu0.1


Access our resources on patching vulnerabilities