4.3
CVSSv2

CVE-2006-0188

Published: 24/02/2006 Updated: 11/10/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

webmail.php in SquirrelMail 1.4.0 to 1.4.5 allows remote malicious users to inject arbitrary web pages into the right frame via a URL in the right_frame parameter. NOTE: this has been called a cross-site scripting (XSS) issue, but it is different than what is normally identified as XSS.

Vulnerable Product Search on Vulmon Subscribe to Product

squirrelmail squirrelmail 1.4.3a

squirrelmail squirrelmail 1.4.4

squirrelmail squirrelmail 1.4.3_r3

squirrelmail squirrelmail 1.4.3_rc1

squirrelmail squirrelmail 1.4.2

squirrelmail squirrelmail 1.4.3

squirrelmail squirrelmail 1.4.6_rc1

squirrelmail squirrelmail 1.4_rc1

squirrelmail squirrelmail 1.4

squirrelmail squirrelmail 1.4.1

squirrelmail squirrelmail 1.4.4_rc1

squirrelmail squirrelmail 1.4.5

Vendor Advisories

Debian Bug report logs - #354063 CVE-2006-0377: IMAP injection attempts Package: squirrelmail; Maintainer for squirrelmail is Jeroen van Wolffelaar <jeroen@wolffelaarnl>; Source for squirrelmail is src:squirrelmail (PTS, buildd, popcon) Reported by: Geoff Crompton <geoffcrompton@strategicdatacomau> Date: Thu, 23 ...
Debian Bug report logs - #354064 CVE-2006-0188: possible XSS through right_main parameter of webmailphp Package: squirrelmail; Maintainer for squirrelmail is Jeroen van Wolffelaar <jeroen@wolffelaarnl>; Source for squirrelmail is src:squirrelmail (PTS, buildd, popcon) Reported by: Geoff Crompton <geoffcrompton@strategi ...
Debian Bug report logs - #354062 CVE-2006-0195: XSS re comments in styles Package: squirrelmail; Maintainer for squirrelmail is Jeroen van Wolffelaar <jeroen@wolffelaarnl>; Source for squirrelmail is src:squirrelmail (PTS, buildd, popcon) Reported by: Geoff Crompton <geoffcrompton@strategicdatacomau> Date: Thu, 2 ...