5.8
CVSSv2

CVE-2004-1101

Published: 10/01/2005 Updated: 11/07/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, allows remote malicious users to cause a denial of service (server crash), leak sensitive pathname information in the resulting error message, and execute a cross-site scripting (XSS) attack via an HTTP request that contains a / (backslash) and arbitrary webscript before the requested file, which leaks the pathname and does not quote the script in the resulting Visual Basic error message.

Vulnerable Product Search on Vulmon Subscribe to Product

tips mailpost 5.1.1_sv

Exploits

source: wwwsecurityfocuscom/bid/11598/info MailPost is reported prone to a cross-site scripting vulnerability This issue presents itself due to insufficient sanitization of user-supplied data and can allow an attacker to execute arbitrary HTML and script code in a user's browser through a malicious error message returned from the applica ...