Back

CVE-2004-0520

Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.

Published: Aug 18, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (21)

Vendor Product Version
open_webmail open_webmail 2.30
open_webmail open_webmail 2.31
open_webmail open_webmail 2.32
sgi propack 3.0
squirrelmail squirrelmail 1.2.0
squirrelmail squirrelmail 1.2.1
squirrelmail squirrelmail 1.2.2
squirrelmail squirrelmail 1.2.3
squirrelmail squirrelmail 1.2.4
squirrelmail squirrelmail 1.2.5
squirrelmail squirrelmail 1.2.6
squirrelmail squirrelmail 1.2.7
squirrelmail squirrelmail 1.2.8
squirrelmail squirrelmail 1.2.9
squirrelmail squirrelmail 1.2.10
squirrelmail squirrelmail 1.2.11
squirrelmail squirrelmail 1.4
squirrelmail squirrelmail 1.4.1
squirrelmail squirrelmail 1.4.2
squirrelmail squirrelmail 1.4.3_rc1

…and 1 more

GitHub Security Advisory GHSA-5vvf-4w4f-hj33

Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote...

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 7.13%

Top 6% most likely to be exploited

Threat Score 29.3 / 100

Data Sources

NVD EPSS GitHub