CVE-2006-0377: CRLF Injection
CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimapmailboxselect command, aka "IMAP injection."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0377?
CVE-2006-0377 is considered a high severity vulnerability due to its potential for remote exploitation through IMAP command injection.
How do I fix CVE-2006-0377?
To mitigate CVE-2006-0377, upgrade to a patched version of SquirrelMail, specifically versions later than 1.4.5.
Which versions of SquirrelMail are affected by CVE-2006-0377?
CVE-2006-0377 affects SquirrelMail versions from 1.4.0 to 1.4.5.
What type of attack is associated with CVE-2006-0377?
CVE-2006-0377 is associated with CRLF injection attacks that allow remote attackers to inject arbitrary IMAP commands.
Can CVE-2006-0377 lead to unauthorized access?
Yes, exploitation of CVE-2006-0377 can lead to unauthorized access to email accounts via manipulated IMAP commands.