First published: Thu May 04 2006(Updated: )
Cross-site scripting (XSS) vulnerability in ow-shared.pl in OpenWebMail (OWM) 2.51 and earlier allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter in (1) openwebmail-send.pl, (2) openwebmail-advsearch.pl, (3) openwebmail-folder.pl, (4) openwebmail-prefs.pl, (5) openwebmail-abook.pl, (6) openwebmail-read.pl, (7) openwebmail-cal.pl, and (8) openwebmail-webdisk.pl. NOTE: the openwebmail-main.pl vector is already covered by CVE-2005-2863.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open Webmail | =2.01 | |
Open Webmail | =1.7 | |
Open Webmail | =2.50 | |
Open Webmail | <=2.51 | |
Open Webmail | =2.41 | |
Open Webmail | =2.00 | |
Open Webmail | =1.81 | |
Open Webmail | =2.30 | |
Open Webmail | =2.21 | |
Open Webmail | =1.71 | |
Open Webmail | =2.31 | |
Open Webmail | =2.10 | |
Open Webmail | =2.20 | |
Open Webmail | =2.40 | |
Open Webmail | =1.8 | |
Open Webmail | =1.90 | |
Open Webmail | =2.32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2190 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To mitigate CVE-2006-2190, you should update OpenWebMail to a version later than 2.51 that does not contain this vulnerability.
CVE-2006-2190 affects OpenWebMail versions 2.51 and earlier, including 1.7 through 2.51.
CVE-2006-2190 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
Yes, CVE-2006-2190 can put user data at risk by allowing attackers to execute scripts in the context of the user's browser.