cscli appsec-rules install crowdsecurity/vpatch-CVE-2002-11311## autogenerated on 2025-04-23 12:56:402name: crowdsecurity/vpatch-CVE-2002-11313description: 'Detects XSS attempts in SquirrelMail 1.2.6/1.2.7 via unsanitized input in addressbook, options, search, and help modules.'4rules:5 - and:6 - zones:7 - URI8 transform:9 - urldecode10 - lowercase11 match:12 type: contains13 value: /src/addressbook.php14 - zones:15 - ARGS_NAMES16 transform:17 - urldecode18 - lowercase19 match:20 type: contains21 value: <22 - and:23 - zones:24 - URI25 transform:26 - urldecode27 - lowercase28 match:29 type: contains30 value: /src/options.php31 - zones:32 - ARGS33 variables:34 - optpage35 transform:36 - urldecode37 - lowercase38 match:39 type: contains40 value: <41 - and:42 - zones:43 - URI44 transform:45 - urldecode46 - lowercase47 match:48 type: contains49 value: /src/search.php50 - zones:51 - ARGS52 variables:53 - mailbox54 - where55 transform:56 - urldecode57 - lowercase58 match:59 type: contains60 value: <61 - and:62 - zones:63 - URI64 transform:65 - urldecode66 - lowercase67 match:68 type: contains69 value: /src/help.php70 - zones:71 - ARGS72 variables:73 - chapter74 transform:75 - urldecode76 - lowercase77 match:78 type: contains79 value: <8081labels:82 type: exploit83 service: http84 confidence: 385 spoofable: 086 behavior: 'http:exploit'87 label: 'SquirrelMail - XSS'88 classification:89 - cve.CVE-2002-113190 - attack.T105991 - cwe.CWE-8092