6.8
CVSSv2

CVE-2004-0337

Published: 23/11/2004 Updated: 11/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote malicious users to execute arbitrary script or HTML as other users via a URL to index.html, followed by a / (slash) and the desired script. NOTE: the vendor states that this bug could not be reproduced, so this issue may be REJECTed in the future.

Vulnerable Product Search on Vulmon Subscribe to Product

software602 602pro lan suite 2002

software602 602pro lan suite 2003

Exploits

source: wwwsecurityfocuscom/bid/9777/info It has been reported that 602Pro LAN Suite Web Mail is prone to a cross-site scripting vulnerability This issue is due to a failure of the application to properly sanitize user input supplied via the URI Attackers may exploit this vulnerability to steal authentication credentials Other attacks ...