Back

MEDIUM

Three XSS issues in SquirrelMail

Published Dec 5, 2006

Description

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) mailto parameter in (a) webmail.php, the (2) session and (3) delete_draft parameters in (b) compose.php, and (4) unspecified vectors involving "a shortcoming in the magicHTML filter."

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Metrics

Weaknesses (0)

No CWE recorded.

References (34)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 5, 2006
Updated Aug 7, 2024
Reserved Nov 28, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Dec 2, 2006