PT-2006-1272 · Microsoft+2 · Internet Explorer+2

Martijn Brinkers

+1

·

Published

2006-02-24

·

Updated

2017-10-11

·

CVE-2006-0195

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SquirrelMail versions 1.4.0 through 1.4.5
Description The issue is related to an interpretation conflict in the MagicHTML filter, allowing remote attackers to conduct cross-site scripting (XSS) attacks. This can be achieved via style sheet specifiers with invalid comments, such as "/" and "/", or a newline in a "url" specifier. Certain web browsers, including Internet Explorer, process these specifiers in a way that enables the attack.
Recommendations For SquirrelMail versions 1.4.0 through 1.4.5, update to a version that fixes the MagicHTML filter interpretation conflict to prevent cross-site scripting attacks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0195
DSA-988-1
RHSA-2006:0283
RHSA-2006_0283

Affected Products

Internet Explorer
Red Hat
Squirrelmail