CVE-2006-3174

Publication date 23 June 2006

Last updated 17 July 2025


Ubuntu priority

Description

Cross-site scripting (XSS) vulnerability in search.php in SquirrelMail 1.5.1 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary HTML via the mailbox parameter.

Status

Package Ubuntu Release Status
squirrelmail 9.10 karmic
Fixed 1.4.10a-2
9.04 jaunty
Fixed 1.4.10a-2
8.10 intrepid
Fixed 1.4.10a-2
8.04 LTS hardy
Fixed 1.4.10a-2
7.10 gutsy
Fixed 1.4.10a-2
7.04 feisty
Fixed 1.4.9a-1ubuntu0.1
6.10 edgy
Fixed 1.4.8-1ubuntu0.1
6.06 LTS dapper Ignored end of life


Access our resources on patching vulnerabilities