5
CVSSv2

CVE-2003-0130

Published: 24/03/2003 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and previous versions does not properly escape HTML characters, which allows remote malicious users to inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.

Vulnerable Product Search on Vulmon Subscribe to Product

ximian evolution 1.0.5

ximian evolution 1.0.6

ximian evolution 1.0.7

ximian evolution 1.0.8

ximian evolution 1.0.3

ximian evolution 1.0.4

ximian evolution 1.2.1

ximian evolution 1.2.2

ximian evolution 1.1.1

ximian evolution 1.2

Exploits

source: wwwsecurityfocuscom/bid/7119/info Ximian Evolution does not properly validate MIME image/* Content-Type fields If an email message contains an image/* Content-Type, any type of data can be embedded where the image information is expected This can be used to embed HTML tags that will be rendered by GTKHtml, bypass policies, or in ...