Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) mailto parameter in (a) webmail.php, the (2) session and (3) delete_draft parameters in (b) compose.php, and (4) unspecified vectors involving "a shortcoming in the magicHTML filter."
References
Link Providers
ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc cve-icon cve-icon
http://docs.info.apple.com/article.html?artnum=306172 cve-icon cve-icon
http://fedoranews.org/cms/node/2438 cve-icon cve-icon
http://fedoranews.org/cms/node/2439 cve-icon cve-icon
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html cve-icon cve-icon
http://secunia.com/advisories/23195 cve-icon cve-icon
http://secunia.com/advisories/23322 cve-icon cve-icon
http://secunia.com/advisories/23409 cve-icon cve-icon
http://secunia.com/advisories/23504 cve-icon cve-icon
http://secunia.com/advisories/23811 cve-icon cve-icon
http://secunia.com/advisories/24004 cve-icon cve-icon
http://secunia.com/advisories/24284 cve-icon cve-icon
http://secunia.com/advisories/26235 cve-icon cve-icon
http://securitytracker.com/id?1017327 cve-icon cve-icon
http://sourceforge.net/project/shownotes.php?release_id=468482 cve-icon cve-icon
http://squirrelmail.org/security/issue/2006-12-02 cve-icon cve-icon
http://www.debian.org/security/2006/dsa-1241 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:226 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2006_29_sr.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_4_sr.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0022.html cve-icon cve-icon
http://www.securityfocus.com/bid/21414 cve-icon cve-icon
http://www.securityfocus.com/bid/25159 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4828 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2732 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/30693 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/30694 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/30695 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-849 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2006-6142 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9988 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2006-6142 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2006-12-05T11:00:00

Updated: 2024-08-07T20:19:34.493Z

Reserved: 2006-11-28T00:00:00

Link: CVE-2006-6142

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2006-12-05T11:28:00.000

Modified: 2017-10-11T01:31:25.097

Link: CVE-2006-6142

cve-icon Redhat

Severity : Moderate

Publid Date: 2006-12-02T00:00:00Z

Links: CVE-2006-6142 - Bugzilla