CVE-2004-1036
Cross-site scripting (XSS) vulnerability in the decoding of encoded text in certain headers in mime.php for SquirrelMail 1.4.3a and earlier, and 1.5.1-cvs before 23rd October 2004, allows remote attackers to execute arbitrary web script or HTML.
Date published : 2004-11-16
http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html
http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html