Current time: 04-24-2014, 01:53 AM Hello There, Guest! (LoginRegister)

Security issues with SquirrelMail
07-22-2010, 01:11 PM
Post: #1
Security issues with SquirrelMail
While I was checking the security of my site, I thought I would also check out my webmail as provided by Dreamhost.

I managed to find an XSS hole in the following url

(edited/snipped by admin for obvious reasons)

So please Dreamhost can we have our mail systems upgraded to secure versions.

I don't fancy getting my email account pwned.

thanks in advance.
Find all posts by this user
07-22-2010, 02:54 PM
Post: #2
RE: Security issues with SquirrelMail
Thank you for bringing this to our attention. As you can see, I have redacted the particulars you shared in an attempt to mitigate to promulgation of the exploit you brought to our attention.

That said, this is being addressed by our security staff and we are actively investigating the issue with the SquirrelMail people.

If you would like to discuss the specifics of this further, please avail yourself of the Private Message function of the forum to contact me directly. Thanks!

--rlparker
--DreamHost Staff
Find all posts by this user


Forum Jump: