7.5
CVSSv2

CVE-2002-0738

Published: 12/08/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

MHonArc 2.5.2 and previous versions does not properly filter Javascript from archived e-mail messages, which could allow remote malicious users to execute script in web clients by (1) splitting the SCRIPT tag into smaller pieces, (2) including the script in a SRC argument to an IMG tag, or (3) using "&={script}" syntax.

Vulnerable Product Search on Vulmon Subscribe to Product

mhonarc mhonarc 2.5

mhonarc mhonarc 2.5.1

mhonarc mhonarc 2.5.2

Vendor Advisories

Jason Molenda and Hiromitsu Takagi found ways to exploit cross site scripting bugs in mhonarc, a mail to HTML converter When processing maliciously crafted mails of type text/html mhonarc does not deactivate all scripting parts properly This is fixed in upstream version 253 If you are worried about security, it is recommended that you disable ...