4.3
CVSSv2

CVE-2002-1958

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in kmMail 1.0, 1.0a, and 1.0b allows remote malicious users to inject arbitrary web script or HTML via (1) javascript in onmouseover or other attributes in "safe" HTML tags such as the "b" tag, or (2) the Subject field.

Vulnerable Product Search on Vulmon Subscribe to Product

kmmail kmmail 1.0

kmmail kmmail 1.0b

kmmail kmmail 1.0a

Exploits

source: wwwsecurityfocuscom/bid/6013/info kmMail does not sufficiently sanitize HTML and script code from the body of e-mail messages As a result, an attacker may send a malicious message to a user of kmMail that includes arbitrary HTML and script code This may allow an attacker to steal cookie-based authentication credentials from use ...