CVE Vulnerabilities

CVE-2006-4019

Published: Aug 11, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variables and read or write the attachments and preferences of other users.

Affected Software

NameVendorStart VersionEnd Version
SquirrelmailSquirrelmail1.4.0 (including)1.4.0 (including)
SquirrelmailSquirrelmail1.4.1 (including)1.4.1 (including)
SquirrelmailSquirrelmail1.4.2 (including)1.4.2 (including)
SquirrelmailSquirrelmail1.4.3 (including)1.4.3 (including)
SquirrelmailSquirrelmail1.4.3_r3 (including)1.4.3_r3 (including)
SquirrelmailSquirrelmail1.4.3_rc1 (including)1.4.3_rc1 (including)
SquirrelmailSquirrelmail1.4.3a (including)1.4.3a (including)
SquirrelmailSquirrelmail1.4.4 (including)1.4.4 (including)
SquirrelmailSquirrelmail1.4.4_rc1 (including)1.4.4_rc1 (including)
SquirrelmailSquirrelmail1.4.5 (including)1.4.5 (including)
SquirrelmailSquirrelmail1.4.6 (including)1.4.6 (including)
SquirrelmailSquirrelmail1.4.6_rc1 (including)1.4.6_rc1 (including)
SquirrelmailSquirrelmail1.4.7 (including)1.4.7 (including)
SquirrelmailSquirrelmail1.4_rc1 (including)1.4_rc1 (including)
SquirrelmailSquirrelmail1.44 (including)1.44 (including)
Red Hat Enterprise Linux 3RedHatsquirrelmail-0:1.4.8-2.el3*
Red Hat Enterprise Linux 4RedHatsquirrelmail-0:1.4.8-2.el4*
SquirrelmailUbuntudapper*
SquirrelmailUbuntudevel*
SquirrelmailUbuntuedgy*
SquirrelmailUbuntufeisty*

References