FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-0195

This CVE name corresponds to:

Entered Topic
2006-02-24 squirrelmail -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-0195
Phase Assigned(20060113)

Description

Interpretation conflict in the MagicHTML filter in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via style sheet specifiers with invalid (1) "/*" and "*/" comments, or (2) a newline in a "url" specifier, which is processed by certain web browsers including Internet Explorer.

References

Source Reference
CONFIRM http://www.squirrelmail.org/security/issue/2006-02-10
DEBIAN DSA-988
FEDORA FEDORA-2006-133
GENTOO GLSA-200603-09
MANDRIVA MDKSA-2006:049
REDHAT RHSA-2006:0283
SGI 20060501-01-U
SUSE SUSE-SR:2006:005
BID 16756
OVAL oval:org.mitre.oval:def:9548
VUPEN ADV-2006-0689
SECTRACK 1015662
SECUNIA 18985
SECUNIA 19131
SECUNIA 19130
SECUNIA 19176
SECUNIA 19205
SECUNIA 19960
SECUNIA 20210
XF squirrelmail-magichtml-xss(24848)