CVE Vulnerabilities

CVE-2006-3665

Published: Jul 18, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

SquirrelMail 1.4.6 and earlier, with register_globals enabled, allows remote attackers to hijack cookies in src/redirect.php via unknown vectors. NOTE: while cookie theft is frequently associated with XSS, the vendor disclosure is too vague to be certain of this.

Affected Software

Name Vendor Start Version End Version
Squirrelmail Squirrelmail 1.4.6 (including) 1.4.6 (including)
Squirrelmail Ubuntu dapper *
Squirrelmail Ubuntu devel *
Squirrelmail Ubuntu edgy *
Squirrelmail Ubuntu feisty *
Squirrelmail Ubuntu gutsy *
Squirrelmail Ubuntu hardy *
Squirrelmail Ubuntu intrepid *
Squirrelmail Ubuntu jaunty *
Squirrelmail Ubuntu karmic *

References