CVE Vulnerabilities

CVE-2006-3665

Published: Jul 18, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

SquirrelMail 1.4.6 and earlier, with register_globals enabled, allows remote attackers to hijack cookies in src/redirect.php via unknown vectors. NOTE: while cookie theft is frequently associated with XSS, the vendor disclosure is too vague to be certain of this.

Affected Software

Name Vendor Start Version End Version
Squirrelmail Squirrelmail 1.4.6 1.4.6

References