CVE-2006-2190: XSS
Cross-site scripting (XSS) vulnerability in ow-shared.pl in OpenWebMail (OWM) 2.51 and earlier allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter in (1) openwebmail-send.pl, (2) openwebmail-advsearch.pl, (3) openwebmail-folder.pl, (4) openwebmail-prefs.pl, (5) openwebmail-abook.pl, (6) openwebmail-read.pl, (7) openwebmail-cal.pl, and (8) openwebmail-webdisk.pl. NOTE: the openwebmail-main.pl vector is already covered by CVE-2005-2863.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2190?
CVE-2006-2190 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2006-2190?
To mitigate CVE-2006-2190, you should update OpenWebMail to a version later than 2.51 that does not contain this vulnerability.
Which versions of OpenWebMail are affected by CVE-2006-2190?
CVE-2006-2190 affects OpenWebMail versions 2.51 and earlier, including 1.7 through 2.51.
What types of attacks can CVE-2006-2190 facilitate?
CVE-2006-2190 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
Is user data at risk due to CVE-2006-2190?
Yes, CVE-2006-2190 can put user data at risk by allowing attackers to execute scripts in the context of the user's browser.