CVE-2007-2589
Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail 1.4.0 through 1.4.9a allows remote attackers to send e-mails from arbitrary users via certain data in the SRC attribute of an IMG element.
Date published : 2007-05-10
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html