CVE-2006-6142

Description

From CVE.org

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) mailto parameter in (a) webmail.php, the (2) session and (3) delete_draft parameters in (b) compose.php, and (4) unspecified vectors involving "a shortcoming in the magicHTML filter."

Statement

Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Frequently Asked Questions

Want to get errata notifications? Sign up here.