CVE
- Id
- 22246
- CVE No.
- CVE-2006-6142
- Status
- Candidate
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) mailto parameter in (a) webmail.php, the (2) session and (3) delete_draft parameters in (b) compose.php, and (4) unspecified vectors involving "a shortcoming in the magicHTML filter."
- Phase
- Assigned (20061128)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
214817 | 22246 | CVE-2006-6142 | CONFIRM:http://sourceforge.net/project/shownotes.php?release_id=468482 | View |
214818 | 22246 | CVE-2006-6142 | CONFIRM:http://squirrelmail.org/security/issue/2006-12-02 | View |
214819 | 22246 | CVE-2006-6142 | CONFIRM:https://issues.rpath.com/browse/RPL-849 | View |
214820 | 22246 | CVE-2006-6142 | CONFIRM:http://docs.info.apple.com/article.html?artnum=306172 | View |
214821 | 22246 | CVE-2006-6142 | APPLE:APPLE-SA-2007-07-31 | View |
214822 | 22246 | CVE-2006-6142 | URL:http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html | View |
214823 | 22246 | CVE-2006-6142 | DEBIAN:DSA-1241 | View |
214824 | 22246 | CVE-2006-6142 | URL:http://www.debian.org/security/2006/dsa-1241 | View |
214825 | 22246 | CVE-2006-6142 | FEDORA:FEDORA-2007-088 | View |
214826 | 22246 | CVE-2006-6142 | URL:http://fedoranews.org/cms/node/2438 | View |
214827 | 22246 | CVE-2006-6142 | FEDORA:FEDORA-2007-089 | View |
214828 | 22246 | CVE-2006-6142 | URL:http://fedoranews.org/cms/node/2439 | View |
214829 | 22246 | CVE-2006-6142 | MANDRIVA:MDKSA-2006:226 | View |
214830 | 22246 | CVE-2006-6142 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:226 | View |
214831 | 22246 | CVE-2006-6142 | REDHAT:RHSA-2007:0022 | View |
214832 | 22246 | CVE-2006-6142 | URL:http://www.redhat.com/support/errata/RHSA-2007-0022.html | View |
214833 | 22246 | CVE-2006-6142 | SGI:20070201-01-P | View |
214834 | 22246 | CVE-2006-6142 | URL:ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc | View |
214835 | 22246 | CVE-2006-6142 | SUSE:SUSE-SR:2006:029 | View |
214836 | 22246 | CVE-2006-6142 | URL:http://www.novell.com/linux/security/advisories/2006_29_sr.html | View |
214837 | 22246 | CVE-2006-6142 | SUSE:SUSE-SR:2007:004 | View |
214838 | 22246 | CVE-2006-6142 | URL:http://www.novell.com/linux/security/advisories/2007_4_sr.html | View |
214839 | 22246 | CVE-2006-6142 | BID:21414 | View |
214840 | 22246 | CVE-2006-6142 | URL:http://www.securityfocus.com/bid/21414 | View |
214841 | 22246 | CVE-2006-6142 | BID:25159 | View |
214842 | 22246 | CVE-2006-6142 | URL:http://www.securityfocus.com/bid/25159 | View |
214843 | 22246 | CVE-2006-6142 | OVAL:oval:org.mitre.oval:def:9988 | View |
214844 | 22246 | CVE-2006-6142 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9988 | View |
214845 | 22246 | CVE-2006-6142 | VUPEN:ADV-2006-4828 | View |
214846 | 22246 | CVE-2006-6142 | URL:http://www.vupen.com/english/advisories/2006/4828 | View |
214847 | 22246 | CVE-2006-6142 | VUPEN:ADV-2007-2732 | View |
214848 | 22246 | CVE-2006-6142 | URL:http://www.vupen.com/english/advisories/2007/2732 | View |
214849 | 22246 | CVE-2006-6142 | SECTRACK:1017327 | View |
214850 | 22246 | CVE-2006-6142 | URL:http://securitytracker.com/id?1017327 | View |
214851 | 22246 | CVE-2006-6142 | SECUNIA:23195 | View |
214852 | 22246 | CVE-2006-6142 | URL:http://secunia.com/advisories/23195 | View |
214853 | 22246 | CVE-2006-6142 | SECUNIA:23322 | View |
214854 | 22246 | CVE-2006-6142 | URL:http://secunia.com/advisories/23322 | View |
214855 | 22246 | CVE-2006-6142 | SECUNIA:23409 | View |
214856 | 22246 | CVE-2006-6142 | URL:http://secunia.com/advisories/23409 | View |
214857 | 22246 | CVE-2006-6142 | SECUNIA:23504 | View |
214858 | 22246 | CVE-2006-6142 | URL:http://secunia.com/advisories/23504 | View |
214859 | 22246 | CVE-2006-6142 | SECUNIA:23811 | View |
214860 | 22246 | CVE-2006-6142 | URL:http://secunia.com/advisories/23811 | View |
214861 | 22246 | CVE-2006-6142 | SECUNIA:24004 | View |
214862 | 22246 | CVE-2006-6142 | URL:http://secunia.com/advisories/24004 | View |
214863 | 22246 | CVE-2006-6142 | SECUNIA:24284 | View |
214864 | 22246 | CVE-2006-6142 | URL:http://secunia.com/advisories/24284 | View |
214865 | 22246 | CVE-2006-6142 | SECUNIA:26235 | View |
214866 | 22246 | CVE-2006-6142 | URL:http://secunia.com/advisories/26235 | View |
214867 | 22246 | CVE-2006-6142 | XF:squirrelmail-mimeheader-xss(30695) | View |
214868 | 22246 | CVE-2006-6142 | URL:http://xforce.iss.net/xforce/xfdb/30695 | View |
214869 | 22246 | CVE-2006-6142 | XF:squirrelmail-webmail-compose-xss(30693) | View |
214870 | 22246 | CVE-2006-6142 | URL:http://xforce.iss.net/xforce/xfdb/30693 | View |
214871 | 22246 | CVE-2006-6142 | XF:squirrelmail-magichtml-messages-xss(30694) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
51362 | JVNDB-2007-000024 | Kerberos administration daemon が初期化されていないポインタを解放する脆弱性 | Kerberos administration daemon (kadmind) には、初期化されていないポインタを解放してしまう脆弱性が存在します。 | CVE-2006-6144 | 22246 | 5 | http://jvndb.jvn.jp/ja/contents/2007/JVNDB-2007-000024.html | View |