CVE DATABASE / CVE-2010-1637
CVE-2010-1637
CVSS 6.5 · MEDIUM
Summary
The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number.
CVSS 3.1 breakdown
| Base score | 6.5 (MEDIUM) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| Attack vector | NETWORK |
| Attack complexity | LOW |
| Privileges required | LOW |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity | NONE |
| Availability | NONE |
Weakness type (CWE)
Affected products
Squirrelmail squirrelmailFedoraproject fedoraApple mac os xApple mac os x serverRedhat enterprise linux desktopRedhat enterprise linux serverRedhat enterprise linux workstation
Check this CVE live
Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.
References
- http://conference.hitb.org/hitbsecconf2010dxb/materials/D1%20-%20Laurent%20Oudot%20-%20Improving%20the%20Stealthiness%20of%20Web%20Hacking.pdf#page=69
- http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043239.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043258.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043261.html
- http://rhn.redhat.com/errata/RHSA-2012-0103.html
- http://secunia.com/advisories/40307
- http://squirrelmail.org/security/issue/2010-06-21
- http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/plugins/mail_fetch/functions.php?r1=13951&r2=13950&pathrev=13951
- http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/plugins/mail_fetch/options.php?r1=13951&r2=13950&pathrev=13951
- http://support.apple.com/kb/HT5130
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:120
- http://www.openwall.com/lists/oss-security/2010/05/25/3
- http://www.openwall.com/lists/oss-security/2010/05/25/9
- http://www.openwall.com/lists/oss-security/2010/06/21/1
Data: NIST NVD. NVD last modified 2026-04-29. Always verify against the vendor advisory before acting.