Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-3665

Опубликовано: 18 июл. 2006
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

SquirrelMail 1.4.6 and earlier, with register_globals enabled, allows remote attackers to hijack cookies in src/redirect.php via unknown vectors. NOTE: while "cookie theft" is frequently associated with XSS, the vendor disclosure is too vague to be certain of this.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:squirrelmail:squirrelmail:1.4.6:*:*:*:*:*:*:*

EPSS

Процентиль: 59%
0.00392
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
около 19 лет назад

SquirrelMail 1.4.6 and earlier, with register_globals enabled, allows remote attackers to hijack cookies in src/redirect.php via unknown vectors. NOTE: while "cookie theft" is frequently associated with XSS, the vendor disclosure is too vague to be certain of this.

debian
около 19 лет назад

SquirrelMail 1.4.6 and earlier, with register_globals enabled, allows ...

github
больше 3 лет назад

SquirrelMail 1.4.6 and earlier, with register_globals enabled, allows remote attackers to hijack cookies in src/redirect.php via unknown vectors. NOTE: while "cookie theft" is frequently associated with XSS, the vendor disclosure is too vague to be certain of this.

EPSS

Процентиль: 59%
0.00392
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other