FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-0188

This CVE name corresponds to:

Entered Topic
2006-02-24 squirrelmail -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-0188
Phase Assigned(20060112)

Description

webmail.php in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary web pages into the right frame via a URL in the right_frame parameter. NOTE: this has been called a cross-site scripting (XSS) issue, but it is different than what is normally identified as XSS.

References

Source Reference
CONFIRM http://www.squirrelmail.org/security/issue/2006-02-01
DEBIAN DSA-988
FEDORA FEDORA-2006-133
GENTOO GLSA-200603-09
MANDRIVA MDKSA-2006:049
REDHAT RHSA-2006:0283
SGI 20060501-01-U
SUSE SUSE-SR:2006:005
BID 16756
OVAL oval:org.mitre.oval:def:10419
VUPEN ADV-2006-0689
SECTRACK 1015662
SECUNIA 18985
SECUNIA 19131
SECUNIA 19130
SECUNIA 19176
SECUNIA 19205
SECUNIA 19960
SECUNIA 20210
XF squirrelmail-webmail-xss(24847)