Description
webmail.php in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary web pages into the right frame via a URL in the right_frame parameter. NOTE: this has been called a cross-site scripting (XSS) issue, but it is different than what is normally identified as XSS.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-988-1 | New squirrelmail packages fix several vulnerabilities |
EUVD |
EUVD-2006-0196 | webmail.php in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary web pages into the right frame via a URL in the right_frame parameter. NOTE: this has been called a cross-site scripting (XSS) issue, but it is different than what is normally identified as XSS. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T16:25:34.005Z
Reserved: 2006-01-12T00:00:00.000Z
Link: CVE-2006-0188
No data.
Status : Modified
Published: 2006-02-24T00:02:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2006-0188
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD