Bug#354064: CVE-2006-0188: possible XSS through right_main parameter of webmail.php

2006-02-23 Thread Thijs Kinkhorst
> The changelog at http://www.squirrelmail.org/changelog.php says for 1.4.6: > - Security: Fix possible cross site scripting through the right_main > parameter of webmail.php. This now uses a whitelist of acceptable > values. [CVE-2006-0188] Hello Jeff, Thanks, I'm aware of it. I'm awai

Bug#354064: CVE-2006-0188: possible XSS through right_main parameter of webmail.php

2006-02-22 Thread Geoff Crompton
Package: squirrelmail Version: 2:1.4.4-7 Severity: important The changelog at http://www.squirrelmail.org/changelog.php says for 1.4.6: - Security: Fix possible cross site scripting through the right_main parameter of webmail.php. This now uses a whitelist of acceptable values. [CVE-2006