Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/11371 | Patch Vendor Advisory |
http://secunia.com/advisories/12789 | Vendor Advisory |
http://marc.info/?l=bugtraq&m=109483971420067&w=2 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17313 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2004-09-09 21:00
Updated : 2017-07-10 18:31
NVD link : CVE-2004-1669
Mitre link : CVE-2004-1669
JSON object : View
CWE
Products Affected
merak
- mail_server
icewarp
- web_mail