CVE-2006-3229: XSS
Cross-site scripting (XSS) vulnerability in Open WebMail (OWM) 2.52, and other versions released before 05/12/2006, allows remote attackers to inject arbitrary web script or HTML via the (1) To and (2) From fields in openwebmail-main.pl, and possibly (3) other unspecified vectors related to "openwebmailerror calls that need to display HTML."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3229?
CVE-2006-3229 is rated as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2006-3229?
To fix CVE-2006-3229, update Open WebMail to version 2.52 or later, which includes patches for the identified vulnerabilities.
What versions of Open WebMail are affected by CVE-2006-3229?
Open WebMail versions before 2.52, including versions 1.7 through 2.51, are affected by CVE-2006-3229.
What is the impact of CVE-2006-3229?
CVE-2006-3229 allows attackers to inject arbitrary web scripts or HTML into the application, potentially leading to theft of user data or session hijacking.
Can CVE-2006-3229 be exploited remotely?
Yes, CVE-2006-3229 can be exploited remotely by attackers through manipulated input in the email fields.