SquirrelMail Prior to 1.4.18 Multiple Vulnerabilities

Summary
SquirrelMail is prone to multiple vulnerabilities, including multiple session-fixation issues, a code-injection issue, and multiple cross-site scripting issues. Attackers may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user, to hijack the session of a valid user, or to inject and execute arbitrary PHP code in the context of the webserver process. This may facilitate a compromise of the application and the computer other attacks are also possible. Versions prior to SquirrelMail 1.4.18 are vulnerable.
References