CVE-2006-0188

Publication date 24 February 2006

Last updated 17 July 2025


Ubuntu priority

Description

webmail.php in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary web pages into the right frame via a URL in the right_frame parameter. NOTE: this has been called a cross-site scripting (XSS) issue, but it is different than what is normally identified as XSS.

Status

Package Ubuntu Release Status
squirrelmail 7.04 feisty
Fixed 1.4.9a-1ubuntu0.1
6.10 edgy
Fixed 1.4.8-1ubuntu0.1
6.06 LTS dapper
Fixed 1.4.6-1ubuntu0.1