CVE Vulnerabilities

CVE-2006-3174

Published: Jun 23, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Cross-site scripting (XSS) vulnerability in search.php in SquirrelMail 1.5.1 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary HTML via the mailbox parameter.

Affected Software

Name Vendor Start Version End Version
Squirrelmail Squirrelmail * 1.5.1 (including)
Squirrelmail Ubuntu dapper *
Squirrelmail Ubuntu devel *
Squirrelmail Ubuntu edgy *
Squirrelmail Ubuntu feisty *
Squirrelmail Ubuntu gutsy *
Squirrelmail Ubuntu hardy *
Squirrelmail Ubuntu intrepid *
Squirrelmail Ubuntu jaunty *
Squirrelmail Ubuntu karmic *

References