Cross-site scripting (XSS) vulnerability in the Autocomplete plugin before 3.0 for SquirrelMail allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Referenceshttp://jvndb.jvn.jp/jvndb/JVNDB-2012-000021http://squirrelmail.org/plugin_view.php?id=32http://jvn.jp/en/jp/JVN56653852/index.html