Vulnerability Name: | CVE-2006-0377 (CCN-24849) | ||||||||||||||||||||
Assigned: | 2006-02-15 | ||||||||||||||||||||
Published: | 2006-02-15 | ||||||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||||||
Summary: | CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka "IMAP injection." | ||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||||||||||||||
References: | Source: SGI Type: UNKNOWN 20060501-01-U Source: CCN Type: BugTraq Mailing List, Mon Feb 27 2006 - 03:10:24 CST [ISecAuditors Advisories] IMAP/SMTP Injection in SquirrelMail Source: MITRE Type: CNA CVE-2006-0377 Source: CCN Type: RHSA-2006-0283 squirrelmail security update Source: CCN Type: SA18985 SquirrelMail Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 18985 Source: SECUNIA Type: UNKNOWN 19130 Source: SECUNIA Type: UNKNOWN 19131 Source: SECUNIA Type: UNKNOWN 19176 Source: SECUNIA Type: UNKNOWN 19205 Source: SECUNIA Type: UNKNOWN 19960 Source: SECUNIA Type: UNKNOWN 20210 Source: CCN Type: SECTRACK ID: 1015662 SquirrelMail Input Validation Bugs Let Remote Users Inject IMAP Commands and Conduct Cross-Site Scripting Attacks Source: SECTRACK Type: Patch 1015662 Source: CCN Type: ASA-2006-096 squirrelmail security update (RHSA-2006-0283) Source: DEBIAN Type: UNKNOWN DSA-988 Source: DEBIAN Type: DSA-988 squirrelmail -- several vulnerabilities Source: CCN Type: GLSA-200603-09 SquirrelMail: Cross-site scripting and IMAP command injection Source: GENTOO Type: UNKNOWN GLSA-200603-09 Source: MANDRIVA Type: UNKNOWN MDKSA-2006:049 Source: SUSE Type: UNKNOWN SUSE-SR:2006:005 Source: FEDORA Type: UNKNOWN FEDORA-2006-133 Source: REDHAT Type: UNKNOWN RHSA-2006:0283 Source: BID Type: UNKNOWN 16756 Source: CCN Type: BID-16756 SquirrelMail Multiple Cross-Site Scripting and IMAP Injection Vulnerabilities Source: CCN Type: SquirrelMail Web site IMAP injection in sqimap_mailbox_select mailbox parameter Source: CONFIRM Type: Patch http://www.squirrelmail.org/security/issue/2006-02-15 Source: VUPEN Type: UNKNOWN ADV-2006-0689 Source: XF Type: UNKNOWN squirrelmail-mailbox-imap-injection(24849) Source: XF Type: UNKNOWN squirrelmail-mailbox-imap-injection(24849) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11470 Source: SUSE Type: SUSE-SR:2006:005 SUSE Security Summary Report | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |