Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php.
No PoCs from references.
- https://github.com/0xget/cve-2001-1473
- https://github.com/20142995/nuclei-templates
- https://github.com/ARPSyndicate/kenzer-templates
- https://github.com/POORVAJA-195/Nuclei-Analysis-main
- https://github.com/gnarkill78/CSA_S2_2024