6.8
CVSSv2

CVE-2002-1307

Published: 29/11/2002 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and previous versions allows remote malicious users to insert script or HTML via an email message with the script in a MIME header name.

Vulnerable Product Search on Vulmon Subscribe to Product

mhonarc mhonarc 2.5.12

mhonarc mhonarc 2.4.4

mhonarc mhonarc 2.5.2

Vendor Advisories

Steven Christey discovered a cross site scripting vulnerability in mhonarc, a mail to HTML converter Carefully crafted message headers can introduce cross site scripting when mhonarc is configured to display all headers lines on the web However, it is often useful to restrict the displayed header lines to To, From and Subject, in which case the v ...

Exploits

source: wwwsecurityfocuscom/bid/6204/info A HTML injection vulnerability has been discovered in Mhonarc An attacker may exploit this issue by sending a specially constructed email containing malicious HTML code in the header section When the vulnerable Mhonarc client converts the message to HTML, any malicious HTML code will be execute ...