CVE-2006-3229
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/06/2006
Last modified:
03/04/2025
Description
Cross-site scripting (XSS) vulnerability in Open WebMail (OWM) 2.52, and other versions released before 05/12/2006, allows remote attackers to inject arbitrary web script or HTML via the (1) To and (2) From fields in openwebmail-main.pl, and possibly (3) other unspecified vectors related to "openwebmailerror calls that need to display HTML."
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:open_webmail:open_webmail:*:*:*:*:*:*:*:* | 2.52 (including) | |
cpe:2.3:a:open_webmail:open_webmail:1.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:open_webmail:open_webmail:1.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:open_webmail:open_webmail:1.71:*:*:*:*:*:*:* | ||
cpe:2.3:a:open_webmail:open_webmail:1.81:*:*:*:*:*:*:* | ||
cpe:2.3:a:open_webmail:open_webmail:1.90:*:*:*:*:*:*:* | ||
cpe:2.3:a:open_webmail:open_webmail:2.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:open_webmail:open_webmail:2.20:*:*:*:*:*:*:* | ||
cpe:2.3:a:open_webmail:open_webmail:2.21:*:*:*:*:*:*:* | ||
cpe:2.3:a:open_webmail:open_webmail:2.30:*:*:*:*:*:*:* | ||
cpe:2.3:a:open_webmail:open_webmail:2.31:*:*:*:*:*:*:* | ||
cpe:2.3:a:open_webmail:open_webmail:2.32:*:*:*:*:*:*:* | ||
cpe:2.3:a:open_webmail:open_webmail:2.41:*:*:*:*:*:*:* | ||
cpe:2.3:a:open_webmail:open_webmail:2.51:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://openwebmail.acatysmoof.com/dev/svn/index.pl/openwebmail/diff/trunk/src/cgi-bin/openwebmail/openwebmail-main.pl?rev1=235%3Brev2%3D236
- http://openwebmail.org/openwebmail/doc/changes.txt
- http://secunia.com/advisories/20714
- http://www.attrition.org/pipermail/vim/2006-June/000902.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27309
- http://openwebmail.acatysmoof.com/dev/svn/index.pl/openwebmail/diff/trunk/src/cgi-bin/openwebmail/openwebmail-main.pl?rev1=235%3Brev2%3D236
- http://openwebmail.org/openwebmail/doc/changes.txt
- http://secunia.com/advisories/20714
- http://www.attrition.org/pipermail/vim/2006-June/000902.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27309