SquirrelMail Multiple Cross-Site Scripting and IMAP Injection Vulnerabilities
BID:16756
Info
SquirrelMail Multiple Cross-Site Scripting and IMAP Injection Vulnerabilities
| Bugtraq ID: | 16756 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-0195 CVE-2006-0377 CVE-2006-0188 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2006 12:00AM |
| Updated: | Dec 15 2006 10:53PM |
| Credit: | Scott Hughes reported the MagicHTML cross-site scripting issue to the vendor. Vicente Aguilera reported the IMAP injection issue. The vendor disclosed the 'webmail.php' cross-site scripting issue. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SquirrelMail SquirrelMail 1.4.8 SquirrelMail SquirrelMail 1.4.6 -rc1 SquirrelMail SquirrelMail 1.4.5 SquirrelMail SquirrelMail 1.4.4 RC1 SquirrelMail SquirrelMail 1.4.4 SquirrelMail SquirrelMail 1.4.3 RC1 SquirrelMail SquirrelMail 1.4.3 r3 SquirrelMail SquirrelMail 1.4.3 a SquirrelMail SquirrelMail 1.4.3 SquirrelMail SquirrelMail 1.4.2 SquirrelMail SquirrelMail 1.4.1 SquirrelMail SquirrelMail 1.4 RC1 SquirrelMail SquirrelMail 1.4 SquirrelMail SquirrelMail 1.2.11 SquirrelMail SquirrelMail 1.2.10 SquirrelMail SquirrelMail 1.2.9 SquirrelMail SquirrelMail 1.2.8 SquirrelMail SquirrelMail 1.2.7 SquirrelMail SquirrelMail 1.2.6 SquirrelMail SquirrelMail 1.2.5 SquirrelMail SquirrelMail 1.2.4 SquirrelMail SquirrelMail 1.2.3 SquirrelMail SquirrelMail 1.2.2 SquirrelMail SquirrelMail 1.2.1 SquirrelMail SquirrelMail 1.2 .0 SquirrelMail SquirrelMail 1.0.5 SquirrelMail SquirrelMail 1.0.4 SGI ProPack 3.0 SP6 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Enterprise Server 9 S.u.S.E. Linux Desktop 1.0 RedHat Linux 9.0 i386 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Desktop 4.0 RedHat Desktop 3.0 Red Hat Fedora Core4 Red Hat Fedora Core3 Red Hat Fedora Core2 Red Hat Fedora Core1 Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: |
SquirrelMail SquirrelMail 1.4.6 -cvs |
Discussion
SquirrelMail Multiple Cross-Site Scripting and IMAP Injection Vulnerabilities
SquirrelMail is susceptible to multiple cross-site scripting and IMAP-injection vulnerabilities. These issues are due to the application's failure to properly sanitize user-supplied input.
An attacker may leverage any of the cross-site scripting issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
An attacker may leverage the IMAP-injection issue to execute arbitrary IMAP commands on the configured IMAP server. This may aid attackers in further attacks and allow them to exploit latent vulnerabilities in the IMAP server.
SquirrelMail is susceptible to multiple cross-site scripting and IMAP-injection vulnerabilities. These issues are due to the application's failure to properly sanitize user-supplied input.
An attacker may leverage any of the cross-site scripting issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
An attacker may leverage the IMAP-injection issue to execute arbitrary IMAP commands on the configured IMAP server. This may aid attackers in further attacks and allow them to exploit latent vulnerabilities in the IMAP server.
Exploit / POC
SquirrelMail Multiple Cross-Site Scripting and IMAP Injection Vulnerabilities
An exploit is not required to carry out these attacks.
An exploit is not required to carry out these attacks.
Solution / Fix
SquirrelMail Multiple Cross-Site Scripting and IMAP Injection Vulnerabilities
Solution:
The vendor has committed fixes to the SquirrelMail CVS repository. Snapshots of the current development version are available from the vendor. For more information on obtaining fixed versions, please contact the vendor.
See the referenced vendor advisories for more information.
SquirrelMail SquirrelMail 1.2.10
SquirrelMail SquirrelMail 1.2.6
SquirrelMail SquirrelMail 1.4
SquirrelMail SquirrelMail 1.4.2
SquirrelMail SquirrelMail 1.4.3 a
SquirrelMail SquirrelMail 1.4.4
SquirrelMail SquirrelMail 1.4.5
Solution:
The vendor has committed fixes to the SquirrelMail CVS repository. Snapshots of the current development version are available from the vendor. For more information on obtaining fixed versions, please contact the vendor.
See the referenced vendor advisories for more information.
SquirrelMail SquirrelMail 1.2.10
-
RedHat squirrelmail-1.4.6-3.rh9.1.legacy.noarch.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/squirrelmail-1. 4.6-3.rh9.1.legacy.noarch.rpm
SquirrelMail SquirrelMail 1.2.6
-
Debian squirrelmail_1.2.6-5_all.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelma il_1.2.6-5_all.deb
SquirrelMail SquirrelMail 1.4
-
RedHat squirrelmail-1.4.6-4.fc1.1.legacy.noarch.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/squirrelmail-1. 4.6-4.fc1.1.legacy.noarch.rpm
SquirrelMail SquirrelMail 1.4.2
-
RedHat squirrelmail-1.4.6-4.fc2.1.legacy.noarch.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/squirrelmail-1. 4.6-4.fc2.1.legacy.noarch.rpm
SquirrelMail SquirrelMail 1.4.3 a
-
RedHat squirrelmail-1.4.6-4.fc3.1.legacy.noarch.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/i386/squirrelmail-1. 4.6-4.fc3.1.legacy.noarch.rpm -
RedHat squirrelmail-1.4.6-4.fc3.1.legacy.noarch.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/x86_64/squirrelmail- 1.4.6-4.fc3.1.legacy.noarch.rpm
SquirrelMail SquirrelMail 1.4.4
-
Debian squirrelmail_1.4.4-8_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelma il_1.4.4-8_all.deb
SquirrelMail SquirrelMail 1.4.5
-
Mandriva squirrelmail-1.4.5-1.2.C30mdk.noarch.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-1.4.5-1.2.C30mdk.src.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva squirrelmail-poutils-1.4.5-1.2.C30mdk.noarch.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
References
SquirrelMail Multiple Cross-Site Scripting and IMAP Injection Vulnerabilities
References:
References:
- RHSA-2006:0283-6 - squirrelmail security update (Red Hat)
- SquirrelMail Changelog (SquirrelMail)
- XMB Homepage (XMB)
- [ISecAuditors Advisories] IMAP/SMTP Injection in SquirrelMail (ISecAuditors Security Advisories)