CVE-2006-6142
Last modified
CVE-2006-6142 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) mailto parameter in (a) webmail.php, the (2) session and (3) delete_draft parameters in (b) compose.php, and (4) unspecified vectors involving "a shortcoming in the magicHTML filter.". EPSS estimates a 1.92% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) mailto parameter in (a) webmail.php, the (2) session and (3) delete_draft parameters in (b) compose.php, and (4) unspecified vectors involving "a shortcoming in the magicHTML filter."
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Squirrelmail | Squirrelmail | 1.4 |
| Squirrelmail | Squirrelmail | 1.4.1 |
| Squirrelmail | Squirrelmail | 1.4.2 |
| Squirrelmail | Squirrelmail | 1.4.3 |
| Squirrelmail | Squirrelmail | 1.4.3_r3 |
| Squirrelmail | Squirrelmail | 1.4.3_rc1 |
| Squirrelmail | Squirrelmail | 1.4.3aa |
| Squirrelmail | Squirrelmail | 1.4.4 |
| Squirrelmail | Squirrelmail | 1.4.4_rc1 |
| Squirrelmail | Squirrelmail | 1.4.5 |
| Squirrelmail | Squirrelmail | 1.4.6 |
| Squirrelmail | Squirrelmail | 1.4.6_cvs |
| Squirrelmail | Squirrelmail | 1.4.6_rc1 |
| Squirrelmail | Squirrelmail | 1.4.7 |
| Squirrelmail | Squirrelmail | 1.4_rc1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-6142?
How severe is CVE-2006-6142?
How do I fix CVE-2006-6142?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-6136IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.…
- CVE-2006-6137Multiple PHP remote file inclusion vulnerabilities in Sisfo …
- CVE-2006-6138Directory traversal vulnerability in download.php in Sisfo K…
- CVE-2006-6139Directory traversal vulnerability in downloadexcel.php in Si…
- CVE-2006-6140PHP remote file inclusion vulnerability in Sisfo Kampus 2006…
- CVE-2006-6141Buffer overflow in Tftpd32 3.01 allows remote attackers to c…
- CVE-2006-6143The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 thr…
- CVE-2006-6144The "mechglue" abstraction interface of the GSS-API library …
- CVE-2006-6145CRYPTOCard CRYPTO-Server before 6.4.56 stores LDAP credentia…
- CVE-2006-6146Buffer overflow in the HPDF_Page_Circle function in hpdf_pag…
- CVE-2006-6147Multiple SQL injection vulnerabilities in JiRos Links Manage…
- CVE-2006-6148Multiple cross-site scripting (XSS) vulnerabilities in submi…
Are you affected by CVE-2006-6142?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
